Remote SOC Analyst: SIEM & Incident Response

Horizon3.ai

United States

Hybrid

USD 124,000 - 161,000

Full time

10 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health insurance
Equity participation
Hybrid & remote work
Parental leave

Job summary

Horizon3.ai is a remote cybersecurity company hiring a mid-level SOC Analyst to monitor, triage, and detect threats within a scalable cloud‑native SIEM environment. You’ll work on alert validation, threat detection tuning, and incident response across AWS, endpoints, and SaaS sources.

Ideal candidates have 3–6 years in SOC, hands‑on SIEM experience (Elastic preferred), and proficiency with KQL/Lucene/SPL, Python/Bash/PowerShell, and cloud security tools.

Qualifications

  • 3–6 years in a SOC or security analyst role.
  • Experience operating an enterprise SIEM (Elastic SIEM preferred) in a cloud environment.
  • Hands-on experience with log analysis, security telemetry, and event correlation.

Responsibilities

  • Monitor, detect, and respond to security events across enterprise environments using the SIEM.
  • Triage, investigate, and validate alerts; escalate as needed with context.
  • Tune and test detection rules to reduce false positives and improve fidelity.
  • Develop dashboards and KPIs to demonstrate SIEM effectiveness.
  • Contribute to incident response playbooks and SOAR automation.
  • Participate in threat hunting and weekly/monthly threat trend reporting.
  • Collaborate with peers and mentors to onboard junior analysts.

Skills

SOC Analyst experience
SIEM monitoring
Alert triage
Detection tuning
Incident response
MITRE ATT&CK
LLM tooling
Python/Bash/PowerShell
Cloud security basics

Education

Bachelor's degree in CS/Cybersecurity

Tools

Elastic SIEM
Splunk
Microsoft Sentinel
QRadar

Job description

Horizon3.ai is a remote cybersecurity company hiring a mid-level SOC Analyst to monitor, triage, and detect threats within a scalable cloud‑native SIEM environment. You’ll work on alert validation, threat detection tuning, and incident response across AWS, endpoints, and SaaS sources.

Ideal candidates have 3–6 years in SOC, hands‑on SIEM experience (Elastic preferred), and proficiency with KQL/Lucene/SPL, Python/Bash/PowerShell, and cloud security tools.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote SOC Analyst – Threat Detection & Incident Response
Remote SOC Analyst – Threat Detection & Incident Response

Horizon3.ai • United States

Remote
USD 124,000 - 161,000
Inclusive Team
Growth Opportunities
Innovative Culture
+2
SOC Analyst
SOC Analyst

Horizon3.ai • United States

Hybrid
USD 124,000 - 161,000
Health insurance
Equity participation
Hybrid & remote work
+1
Senior SOC Analyst
Senior SOC Analyst

Soni • Philadelphia

On-site
USD 90,000 - 120,000
Remote SOC Analyst - SIEM & Threat Response
Remote SOC Analyst - SIEM & Threat Response

Fusion Technology • Washington

On-site
USD 80,000 - 120,000
Best-in-class matching 401K program
Comprehensive healthcare plan
Paid certifications and training
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Senior SOC Analyst: Lead Incident Response & Threat Hunting
Senior SOC Analyst: Lead Incident Response & Threat Hunting

Confidential • Houston (TX)

Hybrid
USD 110,000 - 150,000
Senior SOC Architect: SIEM, SOAR & Threat Hunting
Senior SOC Architect: SIEM, SOAR & Threat Hunting

Jobtailor • Duluth (GA)

On-site
USD 90,000 - 120,000
Senior SOC Lead: Threat Hunting & IR (Remote)
Senior SOC Lead: Threat Hunting & IR (Remote)

SPS Commerce • Minneapolis (MN)

Hybrid
USD 108,000 - 140,000
SOC Analyst – Splunk & SIEM (Remote, US)
SOC Analyst – Splunk & SIEM (Remote, US)

WinTrio LLC • United States

On-site
USD 80,000 - 120,000
Healthcare (Medical, Dental, Vision)
401(k) Plan
Paid Time Off (PTO)
+1
Senior L3 SOC Analyst — Remote Incident Lead
Senior L3 SOC Analyst — Remote Incident Lead

Hamilton Barnes ? • United States

Remote
AUD 127,000 - 184,000
Fully remote role
Collaborative SOC team
Opportunity to grow technical and leadership skills