Remote SOC Cyber Analyst: Threat Detection & Incident Response

Arcfield

Newport (RI)

On-site

USD 64,000 - 112,000

Full time

8 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Health Insurance
Life Insurance
Paid Time Off
Holiday Pay
Disability Insurance (Short/Long Term)
Retirement and Savings

Job summary

Arcfield is seeking a Security Operations Center professional in the United States to monitor and analyze security events with Splunk and Airlock Digital, investigate alerts, and coordinate incident response. The role emphasizes threat detection, analytics development, and cross-domain logs interpretation.

Candidates should have strong SIEM/XDR experience, AD and Windows Server knowledge, and a DoD clearance.

Qualifications

  • BS 2-4 Years, MS 0-2 6+ Years experience in Security Operations Center processes and using SIEM and XDR tools
  • Security Operations Center Analyst: Understand and respond to security detections in a SIEM adhering to Incident Response Processes. Ability to collect relevant information from network and host logs, correlate events together to develop incident timelines and deduce root cause. Collaborate with ISSOs and engineers/developers/admins to resolve security incidents
  • Strong background in Security Compliance & Vulnerability Management. Familiarity with adhering to Cybersecurity Standard Operating Procedures, ability to review and update SOP documents for clarity and accuracy.
  • Prior experience with deploying enterprise tools on Domain Computers, including Antivirus, endpoint protection, and vulnerability scanning
  • Proficient in Active Directory (AD) & Domain Controller (DC) Administration
  • Knowledge of Windows Server Administration, including Windows Server 2019/2022/2025 internals, registry, event logs, and system services
  • Experience with Windows security baselines (CIS, DISA STIG)
  • CompTIA Security+ CE
  • Active Secret DoD Security Clearance required for this role

Responsibilities

  • Monitor and analyze security events in Splunk and Airlock Digital. Analyst on Duty: Investigate alerts that are triggered in the Splunk Console to determine if a threat or normal activity is allowed in the environment.
  • Provide threat detection and incident response to mitigate risks to the Network
  • Security Detection Engineering: troubleshoot, improve and develop security detection analytics. able to determine detection gaps and draft analytics to correct them
  • Experience in interpreting activity to determine what is malicious vs expected from a variety of sources such as Windows and Linux workstations and servers, Firewall, Switch, Router, Endpoint Security, Wireless Intrusion Detection, and other security and application logs Proficiency in scripting languages (PowerShell, Python, Bash, etc.)

Skills

Scripting languages
PowerShell
Python
Bash
Threat detection
Incident response

Education

Bachelor's degree
Master's degree

Tools

Splunk
Airlock Digital
SIEM
XDR

Job description

Arcfield is seeking a Security Operations Center professional in the United States to monitor and analyze security events with Splunk and Airlock Digital, investigate alerts, and coordinate incident response. The role emphasizes threat detection, analytics development, and cross-domain logs interpretation.

Candidates should have strong SIEM/XDR experience, AD and Windows Server knowledge, and a DoD clearance.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations Center Cyber Analyst
Security Operations Center Cyber Analyst

Arcfield • Newport (RI)

On-site
USD 64,000 - 112,000
Health Insurance
Life Insurance
Paid Time Off
+3
Remote SOC Analyst - Threat Detection & Response
Remote SOC Analyst - Threat Detection & Response

Phase2 Technology • Columbia (MD)

On-site
USD 69,000 - 158,000
SOC Analyst – Splunk & SIEM (Remote, US)
SOC Analyst – Splunk & SIEM (Remote, US)

WinTrio LLC • United States

On-site
USD 80,000 - 120,000
Healthcare (Medical, Dental, Vision)
401(k) Plan
Paid Time Off (PTO)
+1
Senior SOC Manager: Incident Response & Security Ops
Senior SOC Manager: Incident Response & Security Ops

ARCO a Family of Construction Companies • St. Louis (MO)

On-site
USD 120,000 - 180,000
Industry-leading bonus program
Company funded retirement
401(k) plan with match
+5
Senior SOC Security Analyst – SIEM/Splunk (DC, Hybrid)
Senior SOC Security Analyst – SIEM/Splunk (DC, Hybrid)

VISUAL SOFT, INC • Washington

Hybrid
USD 110,000 - 150,000
PTO 3 weeks, sick leave included
50% health and dental insurance for员工
401k with company match
Remote SOC Analyst: MDR/XDR Threat Defender
Remote SOC Analyst: MDR/XDR Threat Defender

viLogics • Ebensburg

Remote
USD 70,000 - 90,000
Cyber Defense Analyst — Incident Response & Threat Hunting
Cyber Defense Analyst — Incident Response & Threat Hunting

Erias Ventures, LLC • Fort Meade (MD)

On-site
USD 210,000 - 232,000
Above market pay
401k with vesting
Spot bonuses
+12
Security Operations Analyst
Security Operations Analyst

The Phoenix Group • Arlington (VA)

On-site
USD 90,000 - 120,000
Security Operation Center (SOC) Analyst – Level II
Security Operation Center (SOC) Analyst – Level II

TAC Integrated Solutions • United States

On-site
USD 90,000 - 130,000
Senior Security Analyst Incident Response
Senior Security Analyst Incident Response

Accrescent Group • Cranberry Township

Hybrid
USD 90,000 - 120,000