Security Operations Center Analyst

Tec-Refresh, Inc.

Andover (MA)

On-site

USD 90,000 - 115,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Tec-Refresh, Inc. is seeking a SOC Analyst to serve as the first line of defense and a proactive steward of environment health for our nationwide MSP/MSSP customer base.

You’ll own alert triage, monitoring, and initial incident response, supported by Level 2/3 engineers to drive proactive health checks and quarterly touchpoints across tenants. Responsibilities include monitoring across environments, incident handling, health cadence, and ensuring compliance with security baselines and vendor

Qualifications

  • 2–4 years in a SOC, IT security, or related technical role (MSP/MSSP experience a plus).
  • Working knowledge of SIEM, EDR/XDR, and common security tooling.
  • Hands-on familiarity with firewall and security platforms such as Fortinet, Palo Alto Networks, or Cisco Meraki.
  • Understanding of network fundamentals, incident response lifecycle, and baseline auditing.

Responsibilities

  • Monitor security alerts and events across multiple customer environments using SIEM, EDR, and related tooling.
  • Triage, validate, and prioritize alerts; investigate potential incidents and rule out false positives.
  • Perform initial incident response — contain, document, and escalate confirmed threats per playbook.
  • Maintain clear case notes and communicate status to internal teams and customers.
  • Assist with alert tuning, detection improvements, and reducing noise across client tenants.
  • Track and follow up on open items to ensure timely resolution and SLA compliance.

Skills

SOC operations
Incident response
Threat detection
Communication
Prioritization

Tools

Fortinet
Palo Alto Networks
Cisco Meraki
SIEM
EDR/XDR

Job description

Tec-Refresh is hiring a SOC Analyst to serve as both the first line of defense and a proactive steward of environment health for our nationwide MSP/MSSP customer base. On the reactive side, you'll own alert triage, monitoring, and initial incident response, so our senior engineers can focus on complex investigations and engineering work. On the proactive side, you'll own a recurring cadence of health checks, patch and version currency, baseline auditing, and quarterly customer touchpoints across your assigned tenants. You will be supported throughout by our Level 2/3 engineers, who own escalations and complex remediation, so you are never on an island. The goal is simple: catch the problem during a health check rather than in an alert.

Salary range:$90,000 – $115,000 base, commensurate with experience

What You'll Do
MONITORING & INCIDENT RESPONSE
  • Monitor security alerts and events across multiple customer environments using SIEM, EDR, and related tooling.
  • Triage, validate, and prioritize alerts; investigate potential incidents and rule out false positives.
  • Perform initial incident response — contain, document, and elevate confirmed threats to senior engineers per playbook.
  • Maintain clear, accurate case notes and communicate status to internal teams and customers.
  • Assist with alert tuning, detection improvements, and reducing noise across client tenants.
  • Track and follow up on open items to ensure timely resolution and SLA compliance.
PROACTIVE SERVICES (ENVIRONMENT HEALTH)
  • Run a recurring health cadence across assigned tenants — monthly automated checks, quarterly deep review.
  • Track firmware and software currency across customer firewalls and security tooling (Fortinet, Palo Alto Networks, Cisco Meraki). Flag end-of-support versions, open PSIRT/CVE exposure, and pending vendor advisories.
  • Prepare and execute firewall and security-tool update packages under Tec-Refresh change control — scoped, scheduled in an approved maintenance window, with rollback documented before the window opens.
  • Audit customer environments against configuration baselines and best-practice standards (CIS Benchmarks, vendor hardening guides, Tec-Refresh internal standards). Document drift and drive remediation to closure.
  • Support security and compliance adherence across the customer base — map findings to applicable frameworks (ISO 27001, SOC 2, NIST CSF, CIS Controls, PCI DSS, HIPAA, as relevant per client) and maintain evidence for audit and annual risk review.
  • Build and maintain the quarterly touchpoint deliverable for each assigned account, including a posture summary, open findings, patch and version status, alert trends, and recommended next actions.
  • Participate in quarterly customer review calls alongside the account lead — present the security portion, answer questions, capture follow-ups, and close the loop on prior-quarter commitments.
What You Bring
  • 2–4 years in a SOC, IT security, or related technical role (MSP/MSSP experience a plus).
  • Working knowledge of SIEM, EDR/XDR, and common security tooling.
  • Hands-on familiarity with firewall and security platforms such as Fortinet, Palo Alto Networks, or Cisco Meraki.
  • Understanding of network fundamentals, common attack techniques, and the incident response lifecycle.
  • Exposure to configuration baselines (CIS Benchmarks, vendor hardening guides) and formal change-control processes.
  • Strong attention to detail, organization, and the ability to prioritize across many customers and a recurring cadence.
  • Clear written and verbal communication — comfortable presenting findings on customer review calls.
  • Security+ or equivalent certification preferred (or willingness to earn within an agreed timeframe).
Nice to Have
  • Experience in a multi-tenant / managed services environment.
  • Familiarity with compliance frameworks (SOC 2, ISO 27001, NIST CSF, PCI DSS, HIPAA) and evidence gathering.
  • Familiarity with MITRE ATT&CK, threat intelligence, or basic scripting (PowerShell, Python).
  • Additional certifications (Network+, CySA+, GSEC, or vendor-specific).
Why Tec-Refresh

Join a growing security team where your work directly protects clients across the country. You'll get hands‑on exposure to a wide range of environments and tools, mentorship from experienced engineers, and a clear path to advance into senior analyst or engineering roles.

Tec-Refresh, Inc. is an Equal Opportunity Employer. We do not discriminate on the basis of race, color, religion, creed, national origin, ancestry, sex, gender identity or expression, sexual orientation, age, physical or mental disability, genetic information, veteran or military status, pregnancy or pregnancy-related condition, marital status, or any other characteristic protected by applicable federal, state, or local law. This commitment applies to all aspects of employment, including recruitment, hiring, training, promotion, compensation, benefits, and termination. In accordance with the Massachusetts Pay Equity Act, we do not seek or rely on a candidate's salary history when making compensation decisions; instead, we base compensation on the role's requirements and responsibilities.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations Center Analyst
Security Operations Center Analyst

TECHEAD • Richmond (VA)

Hybrid
USD 80,000 - 100,000
Director of IT Security Operations
Director of IT Security Operations

The Security Executive Council • United States

Remote
USD 170,000 - 210,000
Medical, dental, and vision coverage
401(k) company match
Generous Paid Time Off
+1
Security Operations Engineer
Security Operations Engineer

MultiPlan • McLean (VA)

On-site
USD 130,000 - 145,000
Health insurance
401k
Bonus opportunity
Senior SOC Analyst
Senior SOC Analyst

FlexTrade • Village of Great Neck (NY)

On-site
USD 120,000 - 180,000
Hybrid work schedule
Professional development budget
Comprehensive benefits
Senior SOC Analyst
Senior SOC Analyst

FlexTrade • Milwaukee (WI)

On-site
USD 110,000 - 140,000
Senior Security Operations Center (SOC) Analyst
Senior Security Operations Center (SOC) Analyst

RiseMe • Holyoke (MA)

On-site
USD 115,000 - 142,000
Hybrid work environment
Relocation assistance
On-call rotation
+7
Security Operations Analyst
Security Operations Analyst

NextGenEnergyJobs • Vienna (VA), Northern (KY)

Hybrid
USD 90,000 - 140,000
Health benefits
401(k) and profit-sharing
Paid holidays
+1
SOC Engineer
SOC Engineer

Amentum • Ellicott City (MD)

On-site
USD 145,000 - 190,000
Health, dental, and vision insurance
Paid time off and holidays
Retirement benefits (401(k) matching)
+6
Senior Security Operations Center (SOC) Analyst
Senior Security Operations Center (SOC) Analyst

Clear Destination Inc. • Holyoke (MA)

Hybrid
USD 115,000 - 142,000
Hybrid work
Relocation assistance
On-call rotation
+7
Tier 2 Cybersecurity Engineer
Tier 2 Cybersecurity Engineer

On Call Computer Solutions, LLC • Houston (TX)

On-site
USD 110,000 - 170,000
Health insurance
Retirement plan
Disability insurance
+3