SOC Analyst
Listed on 2026-07-20
-
IT/Tech
Cybersecurity
Grow with us
Ericsson Inc. does not sponsor US work authorizations for this job position, including H-1B, O-1, and TN. Ericsson also does not hire F-1’s working on EAD for this position.
You need to be a US citizen and embody a merit-based, results-driven mindset, unencumbered by other topics competing for mental bandwidth. Your working hours are 10:30AM–6:30PM CT (11:30AM–7:30PM during Daylight Saving Time), and work is only done from the office. You will be required to work one weekend a month.
We are now looking for a SOC analyst in our global Cyber Defense Center (CDC). We detect and respond to cyber attacks originating from external threat actors and ensure we are one step ahead of adversaries.
CDC’s focus is on sophisticated antagonistic threat actors (APT’s) who can do the most harm to Ericsson as a company. Our focus is not on cyber hygiene.
The SOC provides 24/7 cyber security monitoring, triage, incident response, and detection engineering focusing on a wide range of threat actors, finding the signal in the noise and responding to the bulk of malicious activities.
Collaborating units- CDC Threat Intelligence, which compiles, analyzes and provides geopolitical and cyber threat intelligence to Ericsson and the CDC.
- CDC Incident Response and Threat Hunting, which focuses on advanced persistent threats (APTs).
- CDC AI, which ensures AI is leveraged to the fullest in automating cyber defense activities and supports security analysts, incident responders, threat hunters, etc. This unit is also specialized in incident response of AI supported and AI native attacks.
- CDC Red Team, which conducts adversary simulation assignments attacking Ericsson impersonating APT’s.
- CDC IT, which operates CDC’s dedicated IT environments and executes IT projects to ensure CDC has outstanding security monitoring coverage and data quality, and whatever IT ability is required to respond to cyber incidents.
- CDC Process & Governance, which manages CDC’s process universe, coordinates incident response, conducts vendor relationship management, etc.
- Work in a follow‑the-sun SOC, triaging and responding to prioritized alerts, supported by the other teams in CDC. You are responsible for validating whether the alert is a true or false positive, whether it is malicious, and respond according to the response plan. You also are responsible for documenting your analysis and conclusions. Where you determine hands‑on keyboard activity or advanced or complex threat actor activity you elevate to the CDC incident response and threat hunting team and support them with scoping, containment and eviction.
- Work alongside agentic AI systems (commercial and in‑house developed) which will provide guidance and automate repetitive and mundane tasks so you can focus on the analytical part of the job instead of the pivoting and data gathering part.
- Provide ideas and concrete contributions to improve and further automate the SOC, including detection engineering, reinforcement learning, Falcon Fusion workflows and Foundry apps.
- Spend a considerable amount of time on skills development using Immersive Labs, on‑the‑job training and quality review & feedback sessions, conferences and peer interaction so you are always up to date on the threat landscape, how to deal with threats on the technologies we have.
- Have 4 plus years of experience with and expertise in triage, response and detection engineering in SOCs.
- Have thorough knowledge of how to use EDR/ITDR/cloud security/SIEM/exposure management, etc. tooling (preferably Crowd Strike Falcon) to make quality judgments on false/true positives and malicious/non‑malicious.
- Have general technical knowledge of a broad area of technologies such as cloud (AWS, and/or GCP and/or Azure), Linux, Windows, network, identity, etc. and have deep technical knowledge of at least one of these technologies.
- Have a good understanding of threat actor TTPs, can recognize the markings of these in telemetry and logs, and know where to look next to validate or determine whether the activity is a true or false positive, and whether it is malicious.
- Have a strong ambition and drive to catch threat…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).