Get more replies from employers
Send a job-specific resume in minutes.
Adept Consulting Services, Inc. is seeking a SOC Analyst to perform on-site information security monitoring and incident response for mission-critical sites in the Harrisburg area.
The role focuses on analyzing logs and alerts, tuning detections, and following playbooks to protect confidentiality, integrity, and availability of assets. On-site shifts include nights, weekends, and holidays.
The SOC Analyst performs event triage and internal SOC escalations to protect the confidentiality, integrity, and availability of the Commonwealth's information technology assets through prompt and accurate threat handling, while also identifying and closing security gaps through detection engineering, threat hunting, intelligence gathering, and investigation, thereby contributing to the continuous improvement of network and security monitoring.
Perform ongoing, on-site information security and network monitoring with proactive response for mission-critical communication sites and systems.
Capture, log, and respond to events received from email, chat, telecommunication systems, and other security systems, ensuring accurate documentation of incoming data.
Perform security investigation for alerts escalated within the Security Operation Center, determining full scope, potential root cause, and potential impact.
Follow, create, and improve established playbooks and SOPs used by the SOC.
Document security incidents, responses, and related information in accordance with established procedures
Analyze advanced logs, network capture, end-point telemetry to identify malicious activity and indicators of compromise (IOCs)
Conduct initial threat hunting to proactively identify security anomalies and adversary activity
Conduct tuning and optimization of existing detection rules, alerts, and correlation logic to reduce false positives and improve detection fidelity.
Participate in root cause analysis or lessons learned sessions.
Monitor external event sources for security intelligence and actionable incidents
Provide incident response support as needed and directed during network and security events providing support for incident resolution.
Maintain flexibility to work in various shift rotations to support 24/7/365 operations, including days, nights, holidays, and weekends.
Performs Other Related Duties As Required.
Make informed and timely decisions on the appropriate response to security alerts.
Unique issues or problems may be escalated to supervisor.
Work is reviewed periodically for adherence to established standards and established schedules.
Mid-level experience in SOC operations and security alert investigation.
Experience with SIEM tools, security queries, reports, and basic scripting.
Ability to analyze logs, network traffic, and endpoint data to identify threats and IOCs.
Experience with threat hunting, incident response, and root-cause analysis.
Ability to tune detection rules and reduce false positives.
Experience following and improving SOC playbooks and procedures.
Strong documentation, troubleshooting, communication, and prioritization skills.
Ability to work independently and as part of a team.
Willingness to work onsite in rotating 24/7/365 shifts, including nights, weekends, and holidays.