SOC Analyst
Listed on 2026-06-30
-
IT/Tech
Cybersecurity
Job Title
SOC Analyst II
LocationRemote/Hybrid
Job OverviewAs a SOC Analyst II, you will be on the front line of cybersecurity—monitoring, investigating, and responding to real‑world threats across a distributed manufacturing environment spanning both traditional IT and OT/ICS networks. You will work a high‑volume alert queue, triage suspicious activity, and drive incidents toward resolution with speed and precision. From phishing and account compromise to anomalous system behavior, you will connect the dots quickly and help contain risk before it escalates.
This role is built for someone with proven, hands‑on SOC experience—comfortable using SIEM and EDR platforms such as Splunk, Sentinel, or Crowd Strike to investigate activity, assess risk, and respond with minimal ramp‑up. Speed matters: you will help meet response SLAs, acknowledge alerts within minutes, and support a 2 PM – 10 PM ET schedule to bridge a critical gap in global SOC coverage.
U.S. citizenship is required for this position. Beyond traditional SOC work, you will strengthen automation, detection engineering, smarter alerting, and response workflows that keep operations resilient. You will partner across Security, IT, Operations, Legal, HR, and external detection partners to protect the people, products, and processes that power the business—including critical systems supporting industrial, defense, and future‑facing operations.
- Monitor, triage, and document security events across endpoint, network, cloud, and OT/ICS telemetry in a 24x7 operational environment.
- Operate, optimize, and tune detection rules, correlating alerts across multiple platforms to maintain unified visibility and platform health.
- Build, maintain, and improve automation and orchestration workflows that streamline alert triage, response actions, and cross‑tool integrations to reduce analyst toil and improve response time.
- Develop and tune MITRE ATT&CK‑aligned detection use cases, translating detection gaps into new logic, automation, or process improvements.
- Support incident response on escalated events, including triage, remediation, root cause analysis, and post‑incident documentation.
- Conduct threat hunting across event data alongside the security engineering and advanced threats teams to surface activity missed by standard monitoring.
- Adhere to SLAs, metrics, and ticket‑handling obligations while contributing to runbook, playbook, and procedure development.
- Support HR‑ and Legal‑driven security actions, including emergency account terminations and evidence preservation for legal holds, executed with strict chain‑of‑custody discipline and discretion.
- Must be a US Citizen for this position.
- 3+ years of information security monitoring, response, or related experience.
- Hands‑on experience with SIEM, EDR/XDR, and threat intelligence platforms, including alert management and detection tuning.
- Demonstrated experience building and maintaining production automation or SOAR workflows.
- Proficiency in Python and/or Bash scripting in a security context.
- Working knowledge of MITRE ATT&CK and its practical application to detection and response.
- Communicates effectively with both technical and non‑technical stakeholders, adapting messaging to the audience.
- Applies an analytical, problem‑solving mindset, approaching investigations with curiosity and rigor.
- Stays organized and efficient while managing multiple priorities under pressure.
- Exercises sound judgment and makes clear decisions in complex, fast‑moving situations.
- Maintains a high degree of integrity and discretion when handling sensitive matters.
- Experience in a manufacturing, industrial, or OT/ICS environment.
- Proficiency with KQL for detection and investigation.
- Relevant certifications such as SANS GCIH, GCIA, or GDAT (CISSP a plus); actively pursuing a relevant certification is acceptable in lieu of an existing credential. Knowledge of compliance frameworks such as CMMC, NIST, PCI, SOX, or HIPAA.
- Bachelor's degree in computer science, information assurance, cybersecurity, MIS, or a related field, or equivalent practical experience.
- Remote/hybrid work…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).