Security Analyst I (SOC)Assignment DetailsDuration: 12-month contractLocation: On-site, Houston, TXSchedule: 24/7 SOC, including nights, weekends, and holidays (40-hour work week, on-call as needed/ emergencies)Hard requirement: CompTIA Security+ certification Position SummaryThe Security Analyst I handles initial monitoring, detection, triage, and escalation of security events in a 24/7 Security Operations Center (SOC). This role is the frontline of cyber defense, using SIEM and SOAR platforms to identify potential threats, investigate alerts, and escalate on time according to established incident response procedures. It suits a motivated, curious, analytically driven person who thinks critically, adapts quickly, and works well in a fast-paced environment. Key ResponsibilitiesMonitoring & Alert TriageMonitor security events and alerts from SIEM platforms (e.g., Splunk) and other security toolsPerform initial triage and investigation to determine severity, scope, and potential impactAnalyze logs, network activity, endpoint data, and email security alerts (e.g., Proofpoint)Enrich alerts with context such as threat intelligence, asset data, and user behaviorIncident Handling & EscalationFollow defined escalation paths to Tier 2/3 analysts based on severity, confidence, and impactDocument incidents, findings, and actions taken in case management systemsExecute basic response actions using SOAR platforms (e.g., Splunk SOAR)Assist with containment actions under guidanceSOC OperationsSupport 24/7 SOC operations, including shift workParticipate in shift handoffsMaintain situational awareness of threatsPlatform & Tool UsageUse Splunk SIEM and Splunk SOAR for automationInvestigate email threats using ProofpointWork with Microsoft and Azure security toolsContinuous ImprovementImprove alert fidelity and reduce false positivesProvide feedback for detection tuningStay current on emerging threatsRequired QualificationsCompTIA Security+ certificationAssociate degree in Cybersecurity, IT, or a related field, OR equivalent SOC experience2+ years in a 24/7 SOC environmentExperience with Splunk, Splunk SOAR, and ProofpointExperience triaging alerts and following escalation processesKnowledge of networking fundamentals and log analysisFamiliarity with Microsoft and Azure platformsPreferred CertificationsCompTIA CySA+Splunk Core Certified UserMicrosoft Security certifications (e.g., SC-200, AZ-500)Core CompetenciesAnalytical thinking, attention to detail, strong communication, adaptability, curiosity and initiative, team collaborationWorking Conditions24/7 SOC environment, including nights, weekends, and holidaysOn-call or extended hours during incidentsSuccess MetricsMean Time to Triage (MTTT)Escalation accuracyFalse positive reductionDocumentation qualitySLA adherenceThis posting is for an existing vacancy.