SOC Analyst
$70,000–$70,000 year
RemoteUnited States
Job Summary
Monitor, investigate, and respond to security incidents and alerts while performing triage, containment, eradication, recovery, and reporting. Develop, tune, and maintain Splunk dashboards, alerts, and detection content; conduct threat hunting and analyze threat intelligence to identify emerging risks. Support and improve incident response playbooks, runbooks, and SOC processes. Produce incident reports, metrics, and security recommendations. Collaborate with internal teams and external stakeholders during investigations. The senior analyst provides technical leadership, mentors analysts, and leads major incident response activities. Both roles support the CNI organization to ensure NIST regulation compliance and drive continuous improvement across SOC and CSIRT functions using Splunk as the primary SIEM platform.
Required Qualifications
- Eligibility for SC Clearance
- Strong experience in SOC operations, incident response and threat detection
- Hands-on- expertise with Splunk Enterprise / Cloud, including SPL and security monitoring
- Knowledge of network, endpoint, cloud and security technologies
- Familiarity with MITRE ATT&CK, NIST incident response frameworks and threat hunting methodologies
- Experience with EDR, IDS/IPS firewalls
- proven experience leading investigations and mentoring security analysts
Desired Qualifications
- Splunk certifications
- GIAC certifications (GCIH, GCIR, GCFA, GMON) or equivalent
- Experience with SOA, Python, Powershell
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.