Security Operations Center (SOC) Analyst / Engineer
- Hiring from
- Probably Worldwide
- Work type
- Remote
- Posted
- Sep 23, 2026
Is this job info correct?
Job Description
This is a remote position.
Security Operations Center (SOC) Analyst / Engineer
Job Details
- Employment Type: Contract
- Work Mode: Remote
- Location: Offshore
- Total Experience Required: 4 to 7 years
- Relevant Experience Required: 3+ years of dedicated experience working within a 24/7 SOC environment running threat detection and incident response
- Mandatory Certification: Certified Information Systems Security Professional (CISSP), CompTIA Security+, CEH (Certified Ethical Hacker), or GIAC Certified Incident Handler (GCIH)
Job Summary
We are seeking an experienced SOC Analyst / Engineer to monitor, detect, analyze, and respond to cyber threats across our global enterprise infrastructure. The ideal candidate will orchestrate real-time security incident monitoring using advanced SIEM/SOAR platforms, perform deep technical analysis of anomalous events, and execute rapid containment workflows to safeguard business networks.
Key Responsibilities
- Monitor real-time enterprise security alerts across a multi-tenant infrastructure, parsing telemetry data from SIEM, EDR, firewalls, network sensors, and cloud logs.
- Lead incident triage and analysis tracks, investigating anomalous events, identifying true positives, and prioritizing security alerts based on risk and operational impact.
- Execute rapid threat containment workflows, neutralizing live compromises, isolating infected endpoints, disabling compromised accounts, and revoking unauthorized access tokens.
- Configure and tune SIEM correlation rules (e.g., Splunk, Microsoft Sentinel) to enhance detection accuracy and systematically eliminate noise and false positives.
- Develop and automate SOAR playbooks (e.g., Palo Alto Cortex XSOAR, Splunk SOAR) to streamline recurring incident response actions and shorten mean time to remediate (MTTR).
- Perform detailed malware analysis and threat hunting sweeps, evaluating suspicious files, malicious scripts, phishing vectors, and indicators of compromise (IOCs).
- Document and report post-incident reviews, mapping threat behaviors directly to the MITRE ATT&CK framework, identifying detection gaps, and tracking infrastructure remediation needs.
Requirements
- 4 to 7 years of core IT systems security experience, with 3+ dedicated years actively executing real-time threat detection and incident response in a mature SOC.
- Strong technical mastery of enterprise SIEM environments, Endpoint Detection and Response tools (EDR/XDR like CrowdStrike, Defender for Endpoint), and packet capture analysis software (Wireshark).
- Deep structural understanding of network architecture, TCP/IP protocols, common attack vectors, application vulnerabilities, and modern operating system security.
- Mandatory certification: Security+, CEH, GCIH, or CISSP.
Preferred Qualifications
- Prior experience writing detection rules using KQL, YARA, or Sigma formatting rules.
- Familiarity with scripting languages (Python, PowerShell) to extend custom security tool automations and log parsing logic.