×
Register Here to Apply for Jobs or Post Jobs. X

Security Operations Center (SOC) Analyst I

Job in Saint Paul, Ramsey County, Minnesota, 55101, USA
Listing for: Minnesota Jobs
Full Time position
Listed on 2026-08-06
Job specializations:
  • IT/Tech
    Cybersecurity, Network Security, Security Management & Operations
Job Description & How to Apply Below

Security Operations Center (SOC) Analyst I

The Security Operations Center (SOC) Analyst I is a frontline cyber defender responsible for monitoring security tools and dashboards to identify indicators of compromise across networks, endpoints, and cloud-hosted systems in mission-critical environments. The role focuses on triaging and analyzing alerts from SIEM and other monitoring platforms, distinguishing true incidents from benign activity and escalating confirmed threats to senior analysts or incident responders.

SOC Analyst I staff support basic threat detection, documentation of security events, and coordination with IT and security teams for initial containment, while contributing to tuning rules, improving playbooks, and maintaining awareness of common attack techniques and vulnerabilities.

Key Responsibilities
  • Monitor SIEM platforms and log analysis tools to triage security alerts across network, system, and application layers, identifying potential indicators of compromise.
  • Investigate suspicious activity using data from firewalls, IDS/IPS, endpoint protection, and cloud security services to identify potential threats and determine whether escalation is warranted.
  • Apply standard incident response playbooks and procedures, including initial containment steps, evidence preservation, and effective handoff to Tier II or incident response teams.
  • Review vulnerability scanning outputs and apply basic risk prioritization concepts to recognize misconfigurations and exploitable weaknesses in enterprise environments.
  • Document security events and incidents with accurate case records and concise reports that support post-incident review and continuous improvement activities.
  • Follow security frameworks and best practices relevant to highly regulated government or enterprise environments, including access control, monitoring, and logging requirements for mission-critical systems.
  • Participate in rule tuning and playbook improvements, providing feedback on false positives, emerging patterns, and common attack vectors, malware behaviors, and phishing techniques.
Required Qualifications
  • Bachelor's Degree in Computer Science, Information Assurance, Cybersecurity, or a related field, or equivalent relevant experience (aligned to Operations Security Planner I standard).
  • Typically 1–3 years of hands-on experience in IT support, networking, or cybersecurity operations roles, including exposure to security monitoring or incident response.
  • Proficiency with SIEM platforms and log analysis tools for monitoring and triaging security alerts across multiple layers (network, system, application).
  • Ability to investigate suspicious activity using data from firewalls, IDS/IPS, endpoint protection, and cloud security services, with foundational knowledge of common attack vectors and malware behaviors.
  • Familiarity with basic incident response processes, including initial containment, evidence preservation, and structured escalation to Tier II or incident response teams.
  • U.S. Citizenship required, with ability to satisfy background investigation requirements appropriate to a federal IT environment.
  • Strong written and verbal communication skills, with attention to detail in documenting incidents and maintaining accurate case records.
Preferred Qualifications
  • Experience with at least one enterprise SIEM (e.g., Splunk, QRadar, Azure Sentinel) and creation or tuning of correlation rules.
  • Foundational cybersecurity certification such as CompTIA Security+, CySA+, or equivalent vendor-neutral credential.
  • Exposure to 24x7 operations or shift-based monitoring environments supporting large, complex networks.
  • Familiarity with vulnerability scanning tools and outputs, and with standard security frameworks used in highly regulated government or enterprise environments.

Compensation ranges for ASM positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.

It is the policy of ASM that an individual's race, color, religion, sex, disability, age, gender identity, veteran status, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.

All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, veteran status, disability, gender identity, or age. All decisions on employment are made to abide by the principle of equal employment.

The physical requirements described in "Knowledge,

Skills and Abilities

" above are representative of those which must be met by an employee to successfully…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary