Overview
Junior Security Operations Center Analyst – TriWest
Get AI-powered advice on this job and more exclusive features.
Responsibilities
- Monitor security alerts and detect potential threats and anomalies in a 24x7x365 Federal SOC environment
- Analyze system and network logs for security events, anomalies, and configuration issues
- Provide written analysis for each security alert and collaborate with Tier 2 SOC analysts for escalations
- Utilize SIEM and SOAR technologies to monitor, manage, and triage security events
- Respond to incidents, conduct threat intelligence analysis, and support incident response activities
- Use enterprise security tools, including NGAV/EDR, vulnerability scanners, and threat intelligence platforms
- Troubleshoot and resolve incidents/service requests using technical expertise
- Detect and understand various attack activities (e.g., reconnaissance, DDoS, malware)
- Manage alert notifications, triage, and initial incident review in SOC operations
- Prioritize events through effective triage and follow Standard Operating Procedures (SOPs)
- Process and triage security alerts from multiple sources (endpoint, SIEM, email, threat intel, etc.)
- Analyze vulnerability announcements, phishing emails, and support Tier 1 incident response
- Correlate events and conduct event timeline analysis across various log sources
- Analyze logs from operating systems (Linux/Windows), network security devices, and enterprise tools
- Demonstrate proficiency with enterprise SIEM/security analytics (Elastic Stack, Splunk)
- Analyze security events from tools such as Crowdstrike and Palo Alto
- Perform basic malware analysis and understand security incident response processes
- Apply knowledge of Federal Security Standards (NIST, DoD) and compliance requirements
- Hold or be working towards certifications such as Sec+, CE, CEH, CySA+, GCIA, GCIH, etc.
- Have a Bachelor’s degree and a minimum of 3 years of related experience
Qualifications
- Hold or be working towards certifications such as Sec+, CE, CEH, CySA+, GCIA, GCIH, etc.
- Have a Bachelor’s degree and a minimum of 3 years of related experience
- Demonstrate proficiency with enterprise SIEM/security analytics (Elastic Stack, Splunk)
Job function & Industry
- Job function: Information Technology
- Industries: Information Services
Location and compensation notes
Salary and location information are provided in the original listing for multiple locations in the United States.