Security Operations Center (SOC) Analyst

Airswift

Houston (TX)

On-site

USD 85,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Airswift is seeking a Security Operations Center (SOC) Analyst in Houston, TX for a 6-month engagement. The role focuses on monitoring, investigating, and coordinating response to cybersecurity events across enterprise environments.

Ideal candidates have 3–5 years of hands-on SOC experience, strong analytical and communication skills, and the ability to work with SIEM/EDR, cloud security, and identity platforms. Remote work is not available and travel may be required.

Qualifications

  • 3-5 years of hands-on SOC operations experience.
  • Strong understanding of SOC workflows and incident response concepts.
  • Experience investigating phishing, malware activity, and attacker techniques.
  • Ability to work with SIEM, EDR, and cloud security alerts.
  • Strong analytical, documentation, and stakeholder communication skills.
  • Ability to collaborate with senior analysts and cross-functional teams.
  • Commitment to continuous learning and SOC process improvement.

Responsibilities

  • Monitor, triage, validate, and investigate security alerts from SIEM, EDR, email security, identity, network, cloud, and other platforms.
  • Analyse indicators of compromise, malware alerts, account compromise indicators, phishing emails, and BEC attempts.
  • Document investigation findings, actions, evidence, recommendations, and response activities in ticketing systems.
  • Coordinate with senior cybersecurity personnel, IT, OT, email administrators, endpoint teams, identity teams, stakeholders, and users during response.
  • Participate in incident response activities, including evidence gathering and lessons learned.
  • Review threat intelligence, vulnerabilities, and advisories to identify impacts.
  • Conduct proactive threat hunting and improve detections, alerting, and workflows.
  • Support phishing simulations, awareness, and operational reporting.
  • Maintain SOC playbooks and SOPs to support analysts.
  • Communicate status, risk, findings, and next steps to technical and non-technical audiences.

Skills

SOC operations
Incident response
Threat monitoring
Phishing investigation
Communication skills
Documentation
Collaboration
Continuous learning

Tools

SIEM
EDR
Email security
Identity security
Cloud security

Job description

Security Operations Center (SOC) Analyst

Duration: 6 months

Location: Houston, TX

Schedule: Monday - Friday: 7am - 4pm

Role Summary The SOC Analyst is responsible for monitoring, investigating, documenting, and coordinating response to cybersecurity events across enterprise environments. This role is designed for an analyst with 3?5 years of hands‑on experience in SOC operations, incident response, phishing investigation, threat monitoring, or related cybersecurity operations. The analyst is expected to communicate clearly, collaborate early with senior cybersecurity personnel and cross‑functional teams, and exercise sound judgment during complex or time‑sensitive investigations.

Key Responsibilities:
  • Monitor, triage, validate, and investigate security alerts from SIEM, EDR, email security, identity, network, cloud, and other cybersecurity platforms.
  • Analyse suspicious activity, indicators of compromise, malware alerts, account compromise indicators, unauthorised access attempts, phishing emails, smishing messages, malicious links, and business email compromise attempts.
  • Document investigation findings, actions taken, supporting evidence, recommendations, and response activities in designated ticketing or case management systems.
  • Coordinate with senior cybersecurity personnel, IT, OT, email administrators, endpoint teams, identity teams, business stakeholders, and affected users to support investigation, containment, remediation, and user guidance.
  • Participate in incident response activities, including evidence gathering, timeline development, stakeholder coordination, lessons learned, and post‑incident improvement efforts.
  • Review threat intelligence, vulnerability disclosures, and security advisories to identify relevant indicators, attacker techniques, and potential impacts to the organisation.
  • Conduct proactive threat hunting and recommend detection improvements, correlation rules, alert tuning, and workflow enhancements.
  • Support security control validation, cybersecurity awareness activities, phishing simulations, vulnerability prioritisation, operational reporting, and metrics development.
  • Maintain and improve SOC playbooks, standard operating procedures, investigation templates, knowledge articles, and analyst handoff practices.
  • Communicate investigation status, risk, findings, and recommended next steps clearly to technical and non‑technical stakeholders.
Must-Have Skills:
  • 3-5 years of hands‑on experience in SOC operations, incident response, phishing investigation, threat monitoring, or related cybersecurity operations.
  • Strong understanding of SOC workflows, incident response concepts, threat intelligence, vulnerability management, and security monitoring fundamentals.
  • Experience investigating phishing, smishing, business email compromise, malware activity, credential compromise, suspicious user behaviour, and common attacker tactics.
  • Ability to work with SIEM, EDR, email security, identity, network, and cloud security alerts.
  • Strong technical analysis, documentation, prioritisation, problem-solving, and customer service skills.
  • Ability to collaborate effectively with senior analysts, incident responders, IT, OT, infrastructure, identity, email, endpoint, and business teams.
  • Clear communication skills with the ability to explain findings, risks, investigation status, and recommended next steps to technical and non‑technical audiences.
  • Commitment to continuous learning, adaptability, and improving SOC processes, detections, and response workflows.
  • Ability to work in a professional office environment and within or alongside an industrial plant environment, with routine use of standard office equipment.
  • Ability to sit and/or stand for a full shift, lift up to 20 lbs. as needed, move throughout office or site locations, and travel to other company work locations if required.
  • TWIC Card (Required).
  • Remote working is not available for this position.
Nice-to-Have:
  • Industry certification such as CompTIA Security+, CompTIA CySA+, Microsoft SC-200, Cisco CyberOps Associate, GSEC, GCIH, CEH, or similar cybersecurity certification (Preferred).
  • Experience writing or modifying SIEM queries, EDR detection logic, threat hunting queries, or basic automation scripts.
  • Knowledge of MITRE ATT&CK, Cyber Kill Chain, NIST incident response concepts, or similar threat and response frameworks.
  • Experience supporting cybersecurity awareness programmes, phishing simulations, vulnerability prioritisation, remediation tracking, control validation, reporting, or exposure management activities.
  • Interest in mentoring junior analysts, improving SOC processes, and contributing to a collaborative, team-oriented security operations culture.
About Airswift:
  • Airswift is an international workforce solutions provider within the energy, process and infrastructure industries.
  • Airswift serves as a strategic partner to clients, offering a turnkey workforce solution to capture and deliver the top talent needed to complete successful projects by aligning with unique project needs.
  • With over 1000 employees and 9,000 contractors operating in over 60 countries, Airswift's geographical reach and pool of talent available is unmatched in the industry.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst: Incident Response & Threat Monitoring
SOC Analyst: Incident Response & Threat Monitoring

Airswift • Houston (TX)

On-site
USD 85,000 - 110,000
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Security Operations Center Analyst
Security Operations Center Analyst

Madison-Davis, LLC • United States

On-site
USD 90,000 - 120,000
SOC Analyst
SOC Analyst

PSG Global Solutions • Dallas (TX)

On-site
USD 90,000 - 120,000
Security Operations Center (SOC) Analyst (Remote)
Security Operations Center (SOC) Analyst (Remote)

Trace3 • Louisville (KY)

On-site
USD 70,000 - 90,000
Comprehensive medical, dental and vision plans
401(k) Retirement Plan with Employer Match
Competitive Compensation
+4
Security Operations Center (SOC) Analyst (Remote)
Security Operations Center (SOC) Analyst (Remote)

Trace3 • Fargo (ND)

On-site
USD 70,000 - 90,000
Comprehensive medical, dental and vision plans
401(k) Retirement Plan with Employer Match
Training and development programs
+1
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

10xTalents • Washington

On-site
USD 80,000 - 110,000
Security Operations Center (SOC) Analyst (Remote)
Security Operations Center (SOC) Analyst (Remote)

Trace3 • Kansas City (KS)

On-site
USD 70,000 - 90,000
Comprehensive medical, dental and vision plans
401(k) Retirement Plan with Employer Match
Competitive Compensation
+2
SOC Engineer
SOC Engineer

No Limit Staffing, Inc. • United States

On-site
USD 90,000 - 120,000
SOC Analyst Tier 2 (Q Clearance)
SOC Analyst Tier 2 (Q Clearance)

ShorePoint, LLC • North Las Vegas (NV)

On-site
USD 80,000 - 100,000
18 days of PTO
11 holidays
85% of insurance premium covered
+2