Security Operations Center (SOC) Analyst I

PB consulting

Houston, TX

Posted On: Oct 05, 2026

Posted On: Oct 05, 2026

Job Overview

Job Type

Full-time

Experience

4 - 8 Years

Salary

Depends on Experience

Work Arrangement

On-Site

Travel Requirement

0%

Required Skills

  • Splunk
  • Splunk SOAR
  • Proofpoint
  • SIEM
  • Security Alert Triage
  • Incident Escalation
  • Log Analysis
  • Networking Fundamentals
  • Microsoft Security
  • Azure
  • CompTIA Security+
Job Description
Position Overview

We are seeking a Security Analyst I to join a 24/7 Security Operations Center (SOC) as a Tier 1 Cybersecurity Analyst. This role will serve as the first line of defense, monitoring, investigating, and responding to security alerts and potential threats.

The Security Analyst I will leverage SIEM and SOAR technologies to perform initial alert triage, investigate suspicious activity, support incident response, and escalate confirmed or complex incidents to appropriate security teams. This is an excellent opportunity for a motivated cybersecurity professional looking to grow their expertise in threat detection, incident response, and security operations.

Roles and Responsibilities
  • Monitor and investigate security alerts using SIEM platforms, including Splunk.

  • Perform initial alert triage to determine severity, impact, validity, and potential business risk.

  • Analyze security logs, network traffic, endpoint activity, and email security events.

  • Enrich security alerts using threat intelligence and relevant contextual information.

  • Identify potential security incidents and escalate them to Tier 2/Tier 3 security teams according to established procedures.

  • Document investigation findings, actions taken, evidence, and incident details within case management systems.

  • Execute basic incident response and automation activities using Splunk SOAR.

  • Support 24/7 SOC operations, including shift coverage, incident handoffs, and operational communications.

  • Assist with detection rule tuning and alert optimization to reduce false positives and improve SOC efficiency.

  • Participate in continuous improvement initiatives related to SOC processes, procedures, and security monitoring.

  • Maintain awareness of current cybersecurity threats, vulnerabilities, attack techniques, and industry trends.

  • Follow established security policies, procedures, escalation paths, and incident response protocols.

Required Qualifications
  • Associate degree in Cybersecurity, Information Technology, or a related field, or equivalent professional experience.

  • CompTIA Security+ certification required.

  • 2+ years of experience in a Security Operations Center (SOC) or cybersecurity operations environment preferred.

  • Hands-on experience with Splunk, Splunk SOAR, and Proofpoint.

  • Experience performing security alert triage and following incident escalation procedures.

  • Knowledge of networking fundamentals, security concepts, and log analysis.

  • Familiarity with Microsoft security technologies and Azure environments.

  • Strong analytical and problem-solving skills.

  • Excellent written and verbal communication skills.

  • Ability to work effectively in a fast-paced, 24/7 SOC environment.

Preferred Qualifications
  • CompTIA CySA+ certification.

  • Splunk Core Certified User certification.

  • Microsoft security certifications such as SC-200 or AZ-500.

  • Experience with threat intelligence, detection engineering, or incident response.

  • Familiarity with security automation and orchestration technologies


Job ID: PC522518


Posted By

Naincy han

Technical Recruiter