Security Operations Center (SOC) Analyst

OSIbeyond L.L.C.

Rockville (MD)

Remote

USD 85,000 - 120,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical insurance
Vision & Dental insurance
Life Insurance
Short Term Disability Insurance
401K

Job summary

OSIbeyond L.L.C. is seeking a SOC Analyst to monitor client environments, analyze threats, and respond to incidents with automation support. You will own live alert queues, triage detections, and ensure clear handoffs between shifts.

Responsibilities include vulnerability scanning, root-cause analyses, and driving automation improvements while maintaining strong client communications and incident reporting.

Qualifications

  • Two+ years in security operations or incident response.
  • Experience with identity, endpoint, and email threats in Microsoft 365 environments.
  • Familiarity with SIEM, EDR, and vulnerability scanning.

Responsibilities

  • Monitor client environments for threats using SIEM/EDR and email security platforms.
  • Triage alerts and determine true positives and severities; manage tickets.
  • Investigate incidents, contain and remediate threats, and document actions clearly.

Skills

Security operations
Incident response
Threat analysis
SIEM knowledge
Microsoft 365

Education

CompTIA Security+
CompTIA Network+

Tools

SentinelOne
Blumira
Entra ID
Tines

Job description

Since 2004, OSIbeyond has delivered managed technology and cybersecurity services on a founding principle: outstanding technical expertise, matched by an exceptional customer experience. Today, that commitment is delivered through OSIbeyond ONE, our integrated technology platform that unifies IT operations, cybersecurity, Microsoft 365, cloud, automation, AI, and expert support into a single, continuously managed environment. The platform is built on a clear operating philosophy: Automation First. AI Enabled. People Powered.

The OSIbeyond Security Operations Center is the cybersecurity engine of that platform. It provides continuous detection, investigation, and response across a diverse portfolio of client environments, including organizations subject to federal compliance frameworks such as CMMC and NIST SP 800-171. The SOC operates on a two-shift, automation-augmented coverage model. Human analysts staff the Day and Evening shifts, and a purpose-built automation layer operates overnight, backed by an on-call analyst, ensuring that every hour of every day is covered by a trained analyst or by an automated response workflow.

About The Role

The SOC Analyst monitors, analyzes, and responds to cybersecurity threats across client environments. The analyst operates the SOC’s security tooling, investigates suspicious activity, contains and remediates confirmed incidents, and communicates findings clearly to clients and internal stakeholders.

During each shift the analyst owns the live alert queue, triaging detections from the SIEM, endpoint, identity, and email security platforms; determining scope and severity; and executing or authorizing the appropriate response. Because the SOC operates on a shift model, the analyst is also responsible for the integrity of coverage: conducting structured handoffs at the end of each shift, reviewing existing alerts at the start of the Day shift, and ensuring that no detection, investigation, or client commitment is left without a clear owner.

Beyond day-to-day operations, the analyst performs scheduled vulnerability scanning, conducts root cause analysis for security incidents, and identifies repetitive manual work that should be transitioned to automation. Performance is measured against response times, investigation quality, SLA adherence, documentation standards, and contributions to the continuous improvement of detection and automation.

Schedule & Shift Model

The SOC operates a two-shift model with 12-hour shifts. Each analyst is assigned to a fixed shift (Day or Evening) and does not rotate between shift times. The two shifts overlap for six hours (11:00 AM to 5:00 PM), providing a structured handoff window and dual-analyst coverage during peak business hours. Overnight coverage (11:00 PM to 5:00 AM) is provided by the SOC’s Tines automation layer, which performs enrichment, containment, and escalation according to documented playbooks. Escalations that exceed the automation’s authority are routed to the on-call SOC Analyst.

Essential Duties & Responsibilities
Security Monitoring & Alert Triage (≈50%)
  • Monitor client environments continuously for security threats using the SIEM, endpoint detection and response, identity protection, and email security platforms
  • Triage inbound alerts by following the automated priority procedure; determine whether each detection represents a true positive, benign activity, or a tuning opportunity
  • Respond to alerts where automation is unable to clearly determine legitimacy and/or severity. Work and complete assigned tickets in accordance with documented standard operating procedures and service level commitments
  • Identify recurring false positives and submit detection-tuning recommendations to the SOC Manager and automation team
Incident Investigation & Response (≈25%)
  • Investigate security incidents including account compromise, business email compromise, social engineering, malware, and ransomware activity
  • Through automated means and manual review, analyze servers, workstations, identities, and other assets suspected of compromise and accurately assess the scope and type of the issue
  • Contain and remediate confirmed threats using approved automation workflows, scripts, policies, playbooks, and platform controls; escalate in accordance with the incident response plan when the situation exceeds the analyst’s authority or expertise
  • Provide accurate, timely, and professionally written incident communications to designated client points of contact and internal stakeholders with the assistance of the SOC Manager or CISO
Vulnerability Management & Security Posture (≈10%)
  • Perform regularly scheduled vulnerability scanning across client environments
  • Support client compliance objectives, including CMMC and NIST SP 800-171 requirements, by producing the monitoring evidence, logs, and reports required by those frameworks
  • Contribute to periodic client security reviews with clear, data-supported observations
Automation Oversight & Continuous Improvement (≈15%)
  • Review the overnight Tines automation log at the start of the Day shift, confirm low confidence actions were appropriate, and remediate or elevate any exceptions
  • While on call, respond to overnight escalations from the automation layer, take ownership of the incident, and document all actions taken for review at the start of the Day shift
  • Identify repetitive manual investigation and response steps and submit them to the automation team as candidates for new automations or expanded playbooks
  • Identify repetitive "false positives" for the SOC Manager to address
  • Test and provide structured feedback on new detections and automation workflows before they are placed into production
  • Track and document all work in the ticketing system with detail sufficient for a peer to resume the work without additional context
General Responsibilities
  • Provide high-quality written and verbal customer service in every client interaction
  • Meet all key performance indicators and notify the SOC Manager promptly when workload or circumstances place a KPI at risk
  • Recognize when an assignment should be escalated and escalation without delay
  • Support peers across both shifts and contribute to a collaborative, accountable team culture
  • Perform other duties as assigned
Success Metrics
  • Mean time to acknowledge and mean time to respond for alerts during the assigned shift
  • Mean time to contain and mean time to resolve for confirmed incidents
  • KPI adherence across all assigned tickets
  • Escalation accuracy: incidents escalated at the appropriate severity and stage, with complete supporting documentation
  • Quality of shift handoffs, measured by open items with a clear owner and no unattended investigations at shift change
  • Accuracy of automated-action validation and exceptions correctly identified in the overnight automation review
  • On-call responsiveness: acknowledgment and response times for overnight escalations during assigned on-call weeks
  • Detection tuning and automation candidates submitted and adopted
  • Documentation quality and completeness of ticket notes, incident reports, and root cause analyses
  • Client satisfaction with incident communications and security reviews
Security Responsibilities
  • Complete training for and maintain awareness of cybersecurity risks, including insider threat, and the appropriate handling of CUI and other regulated data
  • Treat client data and OSIbeyond data as sensitive, and do not disclose, release, or otherwise transfer it outside of OSIbeyond or client environments without written permission
  • Follow cybersecurity requirements as described in the Employee Handbook and other OSIbeyond policies
  • Immediately follow incident response procedures when a security incident or concern is identified
  • Assist with the escorting or monitoring of visitors when working onsite
  • Monitor alerts from the SIEM and related security platforms, conduct vulnerability scans, and review and update logged events
Qualifications
Experience
  • Two or more years of experience in security operations, incident response, or systems administration with a demonstrable security focus; managed service provider experience is strongly preferred
  • Demonstrated experience investigating and responding to identity, endpoint, and email-based threats in Microsoft 365 environments
Security Operations Skills
  • Working knowledge of SIEM operations, log analysis, and alert triage methodology
  • Understanding of common attack techniques and the MITRE ATT&CK framework, and the ability to map observed activity to adversary behavior
  • Familiarity with endpoint detection and response, identity protection, and email security controls and their remediation actions
  • Ability to perform disciplined, well-documented investigations
Systems & Network Knowledge
  • Solid understanding of Microsoft 365 and Entra ID administration, including conditional access, authentication methods, and audit logging
  • Working knowledge of Windows server and workstation operating systems, Active Directory, and core networking concepts (TCP/IP, DNS, firewalls, VPN)
  • Familiarity with vulnerability scanning platforms and remediation workflows
Automation & Operational Skills
  • Comfort operating within an automation-first environment, including validating and troubleshooting the output of automated playbooks (Tines or comparable SOAR tooling)
  • Basic scripting or query proficiency (PowerShell, KQL, or similar) sufficient to enrich investigations and validate data
  • Disciplined ticket hygiene and documentation habits; ability to write clear, professional client-facing communications
  • Reliability and self-management appropriate to a remote, shift-based role with defined coverage responsibilities
Additional Desirable Qualifications
  • Experience supporting clients subject to CMMC, NIST SP 800-171, or similar regulatory frameworks
  • Prior experience contributing to detection engineering or automation playbook development
  • Experience in a 24x7 or shift-based security operations environment
KNOWLEDGE & CERTIFICATIONS

Tooling Environment: SIEM and extended detection and response platforms; Sentinel One and Blumira; Entra ID identity protection; Tines security automation; vulnerability scanning platform; Autotask professional services automation (ticketing); Microsoft Teams for internal collaboration.

Required Certifications (or attainment within the first six months)

CompTIA Security+

CompTIA Network+

Preferred Certifications

CompTIA SecurityX (CASP+) or other DoD 8140 Level II certification

Position
  • Location - Remote from the United States, must be willing to work EST hours
  • Shift Schedule: 11:00am-11:00pm EST
  • Employment Type - Full time
Benefits
  • Medical Insurance - OSIbeyond pays 75% of the premium for the Employee's base medical plan
  • Vision and Dental Insurance - OSIbeyond pays 75% of the premium for the Employee's plans
  • Life Insurance - OSIbeyond pays 100% of the premium for the Employee's plans
  • Short Term Disability Insurance - OSIbeyond pays 100% of the premium for the Employee's plans
  • 401K - OSIbeyond matches up to 4%
  • PTO/Holidays - 9 paid Holidays and accrual based PTO which increases with tenure, new hires start out with 2 weeks.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations Center (SOC) Analyst - Remote
Security Operations Center (SOC) Analyst - Remote

OSIbeyond L.L.C. • United States

Remote
USD 70,000 - 110,000
Medical Insurance
Vision and Dental Insurance
Life Insurance
+2
Security Operations Center (SOC) Analyst - Remote
Security Operations Center (SOC) Analyst - Remote

OSIbeyond L.L.C. • Rockville (MD)

Remote
USD 70,000 - 105,000
Medical Insurance
Vision Insurance
Dental Insurance
+4
Level 2 Engineer (Human Support) - Remote
Level 2 Engineer (Human Support) - Remote

OSIbeyond L.L.C. • Rockville (MD)

Remote
USD 90,000 - 120,000
Medical Insurance
Vision and Dental Insurance
Life Insurance
+3
Level 2 Engineer (Human Support)
Level 2 Engineer (Human Support)

OSIbeyond L.L.C. • Rockville (MD)

On-site
USD 55,000 - 72,000
Medical Insurance
Vision and Dental Insurance
Life Insurance
+3
SOC Analyst II
SOC Analyst II

Sentinel Blue • United States

Remote
USD 90,000 - 130,000
Healthcare coverage
Paid certification and training
Vacation and holidays
+1
SOC Analyst I
SOC Analyst I

SOClogix, Inc. • Catonsville (MD)

On-site
USD 55,000 - 75,000
Health insurance
Dental insurance
Vision insurance
+6
Security Engineer II
Security Engineer II

Healthcare Outcomes Performance Co. (HOPCo) • Phoenix (AZ)

On-site
USD 120,000 - 170,000
Director of IT Security Operations
Director of IT Security Operations

The Security Executive Council • United States

On-site
USD 170,000 - 210,000
Medical, dental, and vision coverage
401(k) company match
Generous Paid Time Off
+1
Senior OT Security Analyst
Senior OT Security Analyst

Jobgether SRL • United States

Remote
USD 77,000 - 104,000
Remote-first environment
Equity package
OT and industrial cybersecurity focus
Sr. Cybersecurity Engineer - HYBRID
Sr. Cybersecurity Engineer - HYBRID

OSI Systems • Hawthorne (CA)

On-site
USD 160,000 - 170,000
401(k) retirement plan
Health plans
Life insurance
+4