Security Operations Center (SOC) Administrator
Role details
Job location
Tech stack
Job description
The Security Operations Center (SOC) Administrator is responsible for administering and maintaining security monitoring technologies, managing security alerts, and supporting incident response activities across Teachers' on-premises and cloud environments. This role ensures the effective operation of SOC tools, contributes to threat detection efforts, and supports the protection of critical information technology (IT) assets., * Administers and maintains Security Information and Event Management (SIEM) platforms, Endpoint Detection and Response (EDR), Extended Detection and Response (XDR), email security tools, network security systems, and cloud security technologies used within the 24/7 Security Operations Center
- Reviews security alerts and perform structured triage, validation, and categorization of events based on documented playbooks and Standard Operating Procedures (SOPs)
- Escalates confirmed high-priority, or complex incidents per policy and procedure
- Supports the incident response lifecycle, including detection, containment actions, evidence collection, and post-incident reviews
- Creates and maintains incident tickets with detailed findings, actions taken, and recommendations
- Supports vulnerability management and threat intelligence teams by reviewing alerts, indicators of compromise (IOCs), and remediation status
- Participates in phishing investigations, malware analysis at a basic level, suspicious login reviews, and policy violation cases
- Ensures SOC runbooks, SOPs, and escalation paths are followed consistently and contribute recommendations for updates when improvements are identified
- Collaborate with other teams including Cybersecurity Operations, Governance, Risk and Compliance (GRC), IT Operations and Applications during investigations
- Maintains awareness of emerging threats, vulnerabilities, and attacker techniques through training and threat briefings
- Performs other duties as needed upon request by immediate supervisor
Requirements
- Bachelor's degree in computer science, Information Systems, Cybersecurity, Engineering, or a related field or a minimum of eight years related experience required
- Minimum one year experience in cybersecurity operation environment, SOC environments, IT security internships, or related role required
- Foundational knowledge of networking concepts (TCP/IP, DNS, HTTP/S) required
- Basic understanding of incident detection, investigation, and escalation processes required
- Basic understanding of Windows and Linux operating systems and log analysis
- Familiarity with common cyber threats such as phishing, malware, brute force attacks, ransomware, and credential abuse
- Exposure to SIEM platforms (e.g., Microsoft Sentinel, Splunk, QRadar) is preferred
- Awareness of EDR/XDR tools such as Microsoft Defender, CrowdStrike, SentinelOne, or similar platforms preferred
- Familiarity with cybersecurity frameworks such as MITRE ATT&CK and NIST CSF is preferred
- Entry-level certifications such as CompTIA Security+, SC-200, or Blue Team Level 1 preferred
- Strong written and verbal communication skills with the ability to clearly document technical findings required
Benefits & conditions
Tuition reimbursement, 401(k), 401(k) matching, Paid time off, Employee discount, Vision insurance, Dental insurance, We provide a competitive compensation and benefits package that includes, but is not limited to: *
- This position is eligible for our annual discretionary bonus program. Some positions within the credit union also qualify for quarterly performance incentives
- Paid time off for vacation, personal days, and holidays
- 401(k) company contribution
- Teachers pays 100% of Dental & Vision premium
- Tuition reimbursement is offered to full-time employees
- Exclusive employee discount of 0.96% APR on credit card loans and a 1.00% APR on all other loans through Teachers
The good faith range for this position is $28.50 - $34.25 an hour. This range is an estimate, based on potential employee qualifications and operational needs. The salary may vary above and below the stated amounts, as permitted by applicable law.