SOC Analyst

Cato Networks

United States

Hybrid

USD 90,000 - 150,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Global team collaboration

Job summary

Cato Networks is seeking a SOC Analyst to join our global security operations in a hybrid capacity. You will monitor real-time security events across cloud and network infrastructure, own SIEM configurations, and drive incident response in a fast-paced 24x7 environment.

You will be the on-site Israel anchor, coordinating with IT, Cyber Security, and R&D while collaborating with offshore teams in the Philippines.

Qualifications

  • Hands-on SOC experience with security operations and incident response.
  • Experience tuning and writing detection rules for SOC tooling.
  • Strong understanding of threat vectors across cloud, network and endpoints.
  • Comfort with AI/LLM-assisted workflows and automation concepts.
  • Excellent communication and coordination across multiple time zones.

Responsibilities

  • Monitor SIEM, EDR, IPS, mail security, CASB, cloud and identity security to identify threats.
  • Investigate, contain and drive resolution of security incidents per procedures.
  • Lead major incident coordination and ensure clear communication and action tracking.
  • Analyze logs, network traffic, and endpoint telemetry to determine root cause and remediation steps.
  • Own day-to-day SIEM operation including data onboarding, dashboards, and health checks.
  • Write and tune detection rules; maintain runbooks and automation workflows.
  • Mentor analysts, coordinate with offshore SOC teams, and contribute to continuous improvements.

Skills

SIEM expertise
EDR experience
Threat hunting
AI/LLM workflows
Incident response
Analytical skills
Stakeholder comms
On-site leadership

Tools

Elastic
CrowdStrike

Job description

Welcome to the future of cloud networking and security!

Cato Networks is the first company to converge enterprise networking and security into one centralized and global service that is delivered by cloud. It is led by networking and security pioneer Shlomo Kramer (Check Point, Imperva) and early investor (Palo Alto Networks, Exabeam, Trusteer and more). Cato’s unique technology inspired a brand-new product category, later named “SASE” by Gartner and a market expected to reach $28.5 billion by 2028.
This is your opportunity to get on the rocket ship and join a company that is building a cutting-edge enterprise network and secure cloud platform, and is on a fast track to becoming the worldwide market leader – don’t miss it!

As a SOC Analyst, you will be part of the team responsible for real-time monitoring, detection, investigation, and response to security incidents affecting our global infrastructure and services, within a 24x7 operational environment.

This is a hybrid analyst and operations role. Beyond investigating incidents, you will own significant parts of how the SOC runs: the SIEM platform, the detection rule lifecycle, exclusion and exception handling, response automation, and the AI-assisted workflows we use to accelerate triage and investigation.

You will be the only SOC analyst based in Israel, while the rest of the analyst teamoperatesfrom the Philippines. You will act as the SOC’s local anchor — the on-site technical counterpart for the Israel-based Cyber Security, IT, Operations, and R&D teams, and the escalation and knowledge bridge between them and the offshore shifts. The role calls for ownership, independence, and the appetite to build and improve,not only tooperate.

Responsibilities
  • Monitoring and Detection:Continuously monitor SIEM, endpoint protection (EDR), IPS, mail security, CASB, cloud, and identity security solutions toidentifypotential threats.
  • Incident Response:Serve as one of the first levels of escalation for security incidents - investigate,contain, and drive resolution before escalating to the senior SecOps members,in accordance withdefined procedures and SLAs.
  • Incident Coordination:Lead coordination of major incidents until ownership is transferred to the relevant SecOps, IT, Operations, or R&D team; ensure clear communication, escalation, and tracking of action items.
  • Threat Analysis:Analyze logs, network traffic, endpoint telemetry, and native (in-tool) alerts todetermineroot cause, scope, impact, and remediation steps.
  • SIEM and Detection Engineering:Own day-to-day operation of the SIEM - data onboarding and ingest pipelines, field mapping and data quality, dashboards and platform health - and write, tune, andmaintaindetection rules while measuring their effectiveness.
  • Exclusion and Exception Management:Own the exclusion and exception lifecycle across the security stack: review requests, assess risk, apply scoped, time-bound exclusions, and revalidate them periodically.
  • Automation and AI-Assisted Operations:Build and maintain automations across the SOC toolchain (enrichment, containment, ticketing, reporting), and design, implement, and validate AI/LLM-based workflows for alert triage, investigation support, and documentation - including guardrails and quality control of AI output.
  • Investigation Documentation:Create andmaintaindetailed incident tickets, including investigation audit trail, action items, and timelines.
  • Technical Leadership:Act as the senior operational reference for the analystteam:help prioritize workload, assure investigation quality,maintainconsistent handling of incidents, escalations, and shift handovers, and mentor analysts on tooling andmethodology.
  • Collaboration:Work closely with the Cyber Security team, IT, Operations, and R&D locally, and with the offshore SOC team across time zones.
  • Continuous Improvement:Drive improvements todetectionlogic, automation, operational runbooks, and shift handover documentation based on lessons learned from incidents.
  • Compliance and Reporting:Support reporting for compliance audits, management reviews, and threat intelligence updates.
Requirements
  • 3–5 years of hands-on experience in a SOC or cybersecurity operations role.
  • Proven experience with a SIEM platform, includingdetectionrule engineering and content development (Advantage: Elastic).
  • Experience with EDR andadditionalsecurity tools and platforms (Advantage: CrowdStrike Falcon).
  • Practical experience using AI/LLM tools in technical workflows, with a clear understanding of their limitations and failure modes.
  • Broad technical foundation across the SOC domain: threat vectors, malware behavior, network protocols, operating system internals, identity, cloud, and SaaS security controls.
  • Strong analytical and problem-solving skills, with the ability to correlate events across multiple data sources and think beyond the alert.
  • High degree of ownership and autonomy - able tooperateas the only analyst on site, set priorities independently, and drive tasks to closure.
  • Excellent communication skills and the ability to work effectively with distributed teams across time zones.
  • Ability to work effectively on time-sensitive tasks, with a service-oriented approach toward internal stakeholders.
  • Proficiencyin written and verbal English isa must.
Advantage
  • Experience building SOAR pipelines or agentic AI workflows in a security context.
  • Experience with cloud security monitoring (AWS, Azure) and container/Kubernetes telemetry.
  • Experience working with or supporting an offshore/outsourced SOC team.
  • Experience with threat intelligence platforms (e.g., MISP) and intel-driven detection.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

On-Site SOC Analyst — AI-Driven Security & SIEM
On-Site SOC Analyst — AI-Driven Security & SIEM

Cato Networks • United States

Hybrid
USD 90,000 - 150,000
Hybrid work model
Global team collaboration
SOC Analyst I
SOC Analyst I

SOClogix, Inc. • Catonsville (MD)

On-site
USD 55,000 - 75,000
Health insurance
Dental insurance
Vision insurance
+6
Senior SOC Analyst (Direct Hire EAD OKAY)
Senior SOC Analyst (Direct Hire EAD OKAY)

Confidential • United States

Hybrid
USD 120,000 - 180,000
Senior SOC Analyst (Direct Hire Fortune 100CO)
Senior SOC Analyst (Direct Hire Fortune 100CO)

Confidential • Houston (TX)

Hybrid
USD 110,000 - 150,000
SOC Analyst
SOC Analyst

PSG Global Solutions • Dallas (TX)

On-site
USD 90,000 - 120,000
SOC Manager with BS Degree
SOC Manager with BS Degree

Acumenz Consulting • United States

On-site
USD 120,000 - 150,000
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

10xTalents • Washington

On-site
USD 80,000 - 110,000
Security Operations Lead
Security Operations Lead

Segment (Twilio) • Foster City (CA)

On-site
USD 140,000 - 210,000
Health, Dental, Vision
401(k)
Paid time off
+2
SOC Analyst 2
SOC Analyst 2

Mbi Llc • Harrisburg

On-site
USD 60,000 - 90,000
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000