Security Operations Center (SOC) Analyst

TriCom Technical Services

Saint Paul (MN)

Hybrid

USD 70,000 - 110,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Contract position
401(k) match
Paid time off
Paid holidays

Job summary

TriCom Technical Services seeks a Security Operations Center Analyst to support and enhance day-to-day cybersecurity operations. This role monitors, investigates, and responds to security events across enterprise systems while helping strengthen the organization’s overall security posture.

The ideal candidate has hands-on experience with security monitoring, incident response, threat hunting, phishing investigations, and modern security platforms including Microsoft Defender XDR, Sentinel, Entra

Qualifications

  • Minimum 2+ years of experience in a Security Operations Center (SOC) or related cybersecurity role.
  • Experience performing security alert triage, remediation, incident investigation, and after-action documentation.
  • Working knowledge of threat hunting techniques including IOC analysis, threat intelligence review, anomaly detection, and suspicious IP investigations.
  • Experience analyzing phishing emails including email header analysis and spoofing identification.
  • Hands-on experience with Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Microsoft Intune.
  • Experience supporting CrowdStrike Endpoint protection and NGSIEM platforms.
  • Experience conducting Active Directory security audits and investigations.
  • Experience managing and updating incidents within ServiceNow.
  • Strong analytical, problem-solving, and troubleshooting skills.
  • Excellent written and verbal communication skills.
  • Close attention to detail and ability to work effectively in a collaborative team environment.

Responsibilities

  • Monitor, investigate, and remediate security alerts across enterprise environments.
  • Perform proactive threat hunting to identify indicators of compromise and potential security risks.
  • Analyze phishing emails and suspicious communications to identify threats and recommend remediation actions.
  • Operate and monitor the organization's security tool stack including Microsoft Defender XDR, Sentinel, Entra ID, Intune, CrowdStrike, and Active Directory auditing solutions.
  • Create, update, elevate, and track security incidents through ServiceNow.
  • Conduct incident documentation, reporting, and after-action reviews.
  • Collaborate with cybersecurity and IT teams to strengthen security controls and improve operational response processes.
  • Stay current on cybersecurity trends, threat intelligence, and evolving attack techniques.

Skills

Incident response
Threat hunting
Phishing investigations
Security monitoring
Collaboration
Communication
Threat intelligence

Tools

Microsoft Defender XDR
Microsoft Sentinel
Microsoft Entra ID
Microsoft Intune
CrowdStrike
NGSIEM
ServiceNow
Active Directory auditing

Job description

Security Operations Center Analyst

TriCom is seeking a Security Operations Center Analyst to support and enhance day-to-day cybersecurity operations. This role will be responsible for monitoring, investigating, and responding to security events across enterprise systems while helping strengthen the organization\'s overall security posture. The ideal candidate will have hands-on experience with security monitoring, incident response, threat hunting, phishing investigations, and modern security platforms including Microsoft Defender XDR, Sentinel, Entra ID, Intune, and CrowdStrike. This is a hybrid position that may require occasional after-hours support during active security incidents.

Responsibilities
  • Monitor, investigate, and remediate security alerts across enterprise environments.
  • Perform proactive threat hunting to identify indicators of compromise and potential security risks.
  • Analyze phishing emails and suspicious communications to identify threats and recommend remediation actions.
  • Operate and monitor the organization\'s security tool stack including Microsoft Defender XDR, Sentinel, Entra ID, Intune, CrowdStrike, and Active Directory auditing solutions.
  • Create, update, elevate, and track security incidents through ServiceNow.
  • Conduct incident documentation, reporting, and after-action reviews.
  • Collaborate with cybersecurity and IT teams to strengthen security controls and improve operational response processes.
  • Stay current on cybersecurity trends, threat intelligence, and evolving attack techniques.
Requirements
  • Minimum 2+ years of experience in a Security Operations Center (SOC) or related cybersecurity role.
  • Experience performing security alert triage, remediation, incident investigation, and after-action documentation.
  • Working knowledge of threat hunting techniques including IOC analysis, threat intelligence review, anomaly detection, and suspicious IP investigations.
  • Experience analyzing phishing emails including email header analysis and spoofing identification.
  • Hands-on experience with:
    • Microsoft Defender XDR;
    • Microsoft Sentinel;
    • Microsoft Entra ID;
    • Microsoft Intune.
  • Experience supporting CrowdStrike Endpoint protection and Next-Generation SIEM (NGSIEM) platforms.
  • Experience conducting Active Directory security audits and investigations.
  • Experience managing and updating incidents within ServiceNow.
  • Strong analytical, problem-solving, and troubleshooting skills.
  • Excellent written and verbal communication skills.
  • Close attention to detail and ability to work effectively in a collaborative team environment.
Preferred
  • Experience supporting municipal, government, or highly regulated environments.
  • Familiarity with security frameworks and cybersecurity best practices.
  • Experience with incident response processes and forensic investigations.
  • Security certifications including Security+, CySA+, GSEC, GCIA, SC-200, or similar.
  • Experience with automation, scripting, or security orchestration tools.
  • Knowledge of emerging cyber threats, attack techniques, and industry threat intelligence sources.

This is a 4-month-plus Contract opportunity with potential for hire with our MN client. Low-cost employee benefits, paid time off, paid Holidays, and a 401(k) (with an immediately vested company match) are available with TriCom during the contract period. H-1B visa sponsorship is not available for this position. No third-parties, please.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations Center Analyst
Security Operations Center Analyst

Charter Solutions • Minneapolis (MN), Saint Paul (MN)

Hybrid
USD 70,000 - 100,000
Hybrid SOC Analyst (Contract) – Threat Hunting & Incident Response
Hybrid SOC Analyst (Contract) – Threat Hunting & Incident Response

TriCom Technical Services • Saint Paul (MN)

Hybrid
USD 70,000 - 110,000
Contract position
401(k) match
Paid time off
+1
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

10xTalents • Washington

On-site
USD 80,000 - 110,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Security Operations Center Analyst
Security Operations Center Analyst

Oxford Global Resources • Virginia (MN)

On-site
USD 120,000 - 180,000
Senior Security Analyst - Contract-to-Hire, SIEM & Threats
Senior Security Analyst - Contract-to-Hire, SIEM & Threats

TriCom Technical Services • Lenexa (KS)

On-site
USD 90,000 - 120,000
401(k) match
Paid time off
Paid Holidays
SOC Analyst I
SOC Analyst I

SOClogix, Inc. • Catonsville (MD)

On-site
USD 55,000 - 75,000
Health insurance
Dental insurance
Vision insurance
+6
Security Operations Analyst
Security Operations Analyst

NextGenEnergyJobs • Vienna (VA), Northern (KY)

Hybrid
USD 90,000 - 140,000
Health benefits
401(k) and profit-sharing
Paid holidays
+1
Sr. Network Analyst
Sr. Network Analyst

MY HR • Austin (TX)

On-site
USD 110,000 - 150,000
Analyst, Cyber Security II
Analyst, Cyber Security II

TALENT Software Services • Columbia (SC)

On-site
USD 90,000 - 140,000