Posted On: Oct 05, 2026
Job Type
Experience
4 - 8 Years
Salary
Depends on Experience
Work Arrangement
Travel Requirement
0%
Required Skills
We are seeking a Security Analyst I to join a 24/7 Security Operations Center (SOC) as a Tier 1 Cybersecurity Analyst. This role will serve as the first line of defense, monitoring, investigating, and responding to security alerts and potential threats.
The Security Analyst I will leverage SIEM and SOAR technologies to perform initial alert triage, investigate suspicious activity, support incident response, and escalate confirmed or complex incidents to appropriate security teams. This is an excellent opportunity for a motivated cybersecurity professional looking to grow their expertise in threat detection, incident response, and security operations.
Monitor and investigate security alerts using SIEM platforms, including Splunk.
Perform initial alert triage to determine severity, impact, validity, and potential business risk.
Analyze security logs, network traffic, endpoint activity, and email security events.
Enrich security alerts using threat intelligence and relevant contextual information.
Identify potential security incidents and escalate them to Tier 2/Tier 3 security teams according to established procedures.
Document investigation findings, actions taken, evidence, and incident details within case management systems.
Execute basic incident response and automation activities using Splunk SOAR.
Support 24/7 SOC operations, including shift coverage, incident handoffs, and operational communications.
Assist with detection rule tuning and alert optimization to reduce false positives and improve SOC efficiency.
Participate in continuous improvement initiatives related to SOC processes, procedures, and security monitoring.
Maintain awareness of current cybersecurity threats, vulnerabilities, attack techniques, and industry trends.
Follow established security policies, procedures, escalation paths, and incident response protocols.
Associate degree in Cybersecurity, Information Technology, or a related field, or equivalent professional experience.
CompTIA Security+ certification required.
2+ years of experience in a Security Operations Center (SOC) or cybersecurity operations environment preferred.
Hands-on experience with Splunk, Splunk SOAR, and Proofpoint.
Experience performing security alert triage and following incident escalation procedures.
Knowledge of networking fundamentals, security concepts, and log analysis.
Familiarity with Microsoft security technologies and Azure environments.
Strong analytical and problem-solving skills.
Excellent written and verbal communication skills.
Ability to work effectively in a fast-paced, 24/7 SOC environment.
CompTIA CySA+ certification.
Splunk Core Certified User certification.
Microsoft security certifications such as SC-200 or AZ-500.
Experience with threat intelligence, detection engineering, or incident response.
Familiarity with security automation and orchestration technologies
Job ID: PC522518
Posted By
Naincy han
Technical Recruiter