- Company Name
- ECLARO
- Job Title
- Security Operations Center Analyst
- Job Description
-
**Job Title:** Security Operations Center Analyst (SOC Analyst I)
**Role Summary:**
Junior SOC analyst supporting a 24x7/365 federal program. Monitors security alerts, performs initial triage, analyzes logs and threats, and documents findings. Escalates complex issues to Tier 2 analysts and follows established SOPs.
**Expectations:**
- Minimum 3 years of hands‑on experience in SOC operations or incident response.
- Ability to work remotely and adhere to a shift‑based schedule covering continuous coverage.
- Proficiency with SIEM/SOAR platforms and adherence to federal security standards (NIST, DoD).
- Strong written communication for clear analysis reports.
**Key Responsibilities:**
- Monitor and analyze system/network logs for security events, anomalies, and configuration issues.
- Perform real‑time alert triage, prioritization, and documentation of findings.
- Investigate and respond to incidents including malware, phishing, DDoS, and reconnaissance activities.
- Utilize SIEM (e.g., Splunk, Elastic Stack) and security tools (CrowdStrike, Palo Alto, NGAV/EDR, vulnerability scanners).
- Conduct threat intelligence research and correlate IOCs from multiple sources (CISA, Threat Client, email security).
- Follow and update Standard Operating Procedures (SOPs) for alert handling, incident escalation, and remediation.
- Support Tier 2 analysts with detailed logs, timeline analysis, and evidence collection.
**Required Skills:**
- SIEM/SOAR operation and log analysis (Splunk, Elastic, etc.).
- Endpoint detection and response (EDR/NGAV) and vulnerability scanning.
- Network security fundamentals (firewall, IDS/IPS, traffic analysis).
- Incident response lifecycle and threat intelligence integration.
- Familiarity with Windows and Linux event logs, network device logs, and cloud environment logs.
- Basic malware analysis techniques.
- Strong analytical, troubleshooting, and documentation abilities.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field *or* equivalent professional experience.
- One or more of the following certifications: CompTIA Security+ (Sec+CE), CEH, CySA+, CCNA Cyber Ops, CCNA Security, GCIA, GCIH, GICSP, Cloud+, SCYBER, PenTest+, CFR.
**Nice‑to‑Have:**
- Experience with FedRAMP cloud security requirements.
- Direct experience with NIST and DoD federal security frameworks.