Security Operations Center Analyst

Madison-Davis, LLCUnited States
ContractOn-siteMidLimited info disclosed
14 views0 applications

Description

100% Remote (United States) Must be able to work Eastern Time (EST) hours A leading financial services organization is expanding its internal Security Operations Center (SOC) and is seeking an experienced Cybersecurity SOC Analyst to help mature enterprise detection and response capabilities. This is an opportunity to join a highly collaborative security team that is moving beyond traditional alert monitoring into advanced threat detection, investigation, automation, and detection engineering. The ideal candidate enjoys solving complex security problems, improving SOC processes, and leveraging modern security technologies to strengthen enterprise defenses. You'll work alongside security engineers, infrastructure teams, and incident responders while helping build a next-generation SOC focused on operational excellence and continuous improvement. What You'll Do: Monitor, triage, investigate, and respond to enterprise security alerts across multiple security platforms. Perform end-to-end incident investigations, including validation, containment, escalation, documentation, and post-incident analysis. Conduct proactive threat hunting activities to identify suspicious behavior before alerts are generated. Develop, optimize, and maintain Splunk SPL searches to improve detection accuracy and visibility. Tune existing detections and reduce false positives through continuous refinement of alert logic. Help develop new detection use cases and correlation rules for emerging threats. Investigate endpoint, identity, email, cloud, and network security events. Collaborate with engineering, infrastructure, and security teams to improve telemetry and monitoring coverage. Assist with security automation initiatives using scripting and modern security tools. Document investigations, incident findings, and operational improvements. Contribute to the continued evolution and maturity of the organization's internal SOC. Required Qualifications: 3–5 years of cybersecurity experience. Minimum of 3 years working within a Security Operations Center (SOC). Hands-on experience performing L1/L2 incident investigations. Strong understanding of: Incident Response Threat Detection Alert Triage Threat Hunting Strong experience with Splunk Enterprise Security/Core . Advanced SPL query writing and log analysis experience. Experience tuning detections and improving alert quality. Experience with enterprise Endpoint Detection & Response (EDR) platforms such as: CrowdStrike Falcon Microsoft Defender SentinelOne Carbon Black Experience investigating phishing, malware, credential compromise, and endpoint security incidents. Familiarity with enterprise email security technologies. Strong communication, documentation, and incident reporting skills. Ability to work a scheduled EST shift.