We are seeking a Tier 1 Cyber Security Analyst to join our overnight SOC operations. Working fully remotely, you will serve as the first line of defense against cyber threats during peak off-peak operational hours. You will monitor security alerts, perform initial triage, analyze raw log data, and elevate validated incidents to higher-tier teams.
Location
Remote, open to candidates anywhere in the U.S.
Key Responsibilities
- 24/7 Threat Monitoring: Actively monitor SIEM dashboards, EDR platforms, and intrusion detection systems (IDS/IPS) for security alerts.
- Alert Triage & Analysis: Investigate low-to-medium risk security events (phishing, malware alerts, brute-force attempts, unauthorized access) to differentiate true threats from false positives.
- Incident Escalation: Document and elevate validated security incidents to Tier 2/3 Analysts or Incident Responders following established standard operating procedures (SOPs).
- Threat Intelligence Integration: Utilize Open Source Intelligence (OSINT) and threat intelligence feeds to contextualize potential security risks.
- Shift Handovers: Conduct detailed, documented shift handoffs with incoming and outgoing security personnel to ensure seamless operational continuity.
Qualifications
Required
- Education/Experience: Associate or Bachelor's degree in Cybersecurity, Computer Science, IT, or equivalent hands-on experience/bootcamp training.
- Certifications: CompTIA Security+, Network+, CySA+, or equivalent foundational cybersecurity certifications.
- Technical Skills: Basic understanding of TCP/IP networking, OSI model, common attack vectors (OWASP Top 10, phishing, ransomware), and system logs (Windows/Linux).
- Tools Experience: Familiarity with SIEM platforms (e.g., Splunk, Microsoft Sentinel), EDR tools (e.g., CrowdStrike, SentinelOne), and ticketing systems.
- Soft Skills: Exceptional attention to detail, strong written/verbal communication, and the ability to work independently during night hours.
Preferred
- 6+ months of prior experience in a SOC, helpdesk, or IT service desk environment.
- Hands-on experience with packet analysis tools (e.g., Wireshark) and log analysis.
- Basic understanding of cloud security concepts (AWS, Azure, GCP)