The Security Operations Center (SOC) Analyst I is a frontline cyber defender responsible for monitoring security tools and dashboards to identify indicators of compromise across networks, endpoints, and cloud‑hosted systems in mission‑critical environments. The role focuses on triaging and analyzing alerts from SIEM and other monitoring platforms, distinguishing true incidents from benign activity and escalating confirmed threats to senior analysts or incident responders. SOC Analyst I staff support basic threat detection, documentation of security events, and coordination with IT and security teams for initial containment, while contributing to tuning rules, improving playbooks, and maintaining awareness of common attack techniques and vulnerabilities. Key Responsibilities Monitor SIEM platforms and log analysis tools to triage security alerts across network, system, and application layers, identifying potential indicators of compromise. Investigate suspicious activity using data from firewalls, IDS/IPS, endpoint protection, and cloud security services to identify potential threats and determine whether escalation is warranted. Apply standard incident response playbooks and procedures, including initial containment steps, evidence preservation, and effective handoff to Tier II or incident response teams. Review vulnerability scanning outputs and apply basic risk prioritization concepts to recognize misconfigurations and exploitable weaknesses in enterprise environments. Document security events and incidents with accurate case records and concise reports that support post‑incident review and continuous improvement activities. Follow security frameworks and best practices relevant to highly regulated government or enterprise environments, including access control, monitoring, and logging requirements for mission‑critical systems. Participate in rule tuning and playbook improvements, providing feedback on false positives, emerging patterns, and common attack vectors, malware behaviors, and phishing techniques. Required Qualifications Bachelor’s Degree in Computer Science, Information Assurance, Cybersecurity, or a related field, or equivalent relevant experience (aligned to Operations Security Planner I standard). Standard-Job-Titles-SharePoint-2-11.xlsx Typically 1–3 years of hands‑on experience in IT support, networking, or cybersecurity operations roles, including exposure to security monitoring or incident response. Proficiency with SIEM platforms and log analysis tools for monitoring and triaging security alerts across multiple layers (network, system, application). Ability to investigate suspicious activity using data from firewalls, IDS/IPS, endpoint protection, and cloud security services, with foundational knowledge of common attack vectors and malware behaviors. Familiarity with basic incident response processes, including initial containment, evidence preservation, and structured escalation to Tier II or incident response teams. U.S. Citizenship required, with ability to satisfy background investigation requirements appropriate to a federal IT environment. Strong written and verbal communication skills, with attention to detail in documenting incidents and maintaining accurate case records. Preferred Qualifications Experience with at least one enterprise SIEM (e.g., Splunk, QRadar, Azure Sentinel) and creation or tuning of correlation rules. Foundational cybersecurity certification such as CompTIA Security+, CySA+, or equivalent vendor‑neutral credential. Exposure to 24x7 operations or shift‑based monitoring environments supporting large, complex networks. Familiarity with vulnerability scanning tools and outputs, and with standard security frameworks used in highly regulated government or enterprise environments. Compensation Ranges Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees. EEO Requirements It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies. All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment. Physical Requirements The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions. Disclaimer The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.
Reliability Centered Maintenance Analyst
Cherokee Federal
Lead Security Operations Center (SOC) Analyst
Livenation
Security Operations Center Analyst II (SOC Analyst II)
Old Second National Bank
Teamcenter Administrator / PLM Engineer (Remote)(Systems Application Analyst 3) 29165
Hii Tsd
Reporting and Analytics Analyst 2 - Government Resource Center
Osu
Technology Solution Center Analyst
Pnc