Security Operations Analyst
Role details
Job location
Tech stack
Job description
UNCOMN is seeking a Security Operations Analyst to support frontline security monitoring and compliance operations. This role is split between operating UNCOMN's compliance evidence engine and serving as a SOC Analyst, helping ensure audit readiness, while monitoring, triaging, and responding to security events across the environment. This is an in-person position, with some remote flexibility, subject to supervisor approval and business needs, and additional key responsibilities include: SOC Analyst Responsibilities
- Monitor, investigate, and respond to security alerts and events across endpoint, network, cloud, identity, email, and SIEM platforms, ensuring timely triage, escalation, and resolution.
- Review logs, detections, and system activity to identify malicious or unauthorized behavior, and support incident response through documentation, evidence collection, and coordination with internal stakeholders or service providers.
- Investigate phishing, malware, account compromise, and other security events, escalating based on severity, business impact, and risk.
- Review vulnerability findings, support risk assessments, and coordinate remediation planning and corrective actions with internal IT and other stakeholders.
- Configure, tune, and optimize endpoint protection and related security tools to strengthen detection coverage and device security.
- Manage firewall rule requests, reviews, and updates in coordination with the IT Service team and engineering stakeholders; review, validate, and test firewall changes; and provide guidance on firewall hardening to support secure, controlled, and business-aligned access.
- Support secure communication and data protection processes, including encrypted email, secure file sharing, and related protected communications tools.
- Test incident response readiness through tabletop exercises and contribute to improvements in playbooks, workflows, and SOC processes.
- Support internal IT with security-related requests, including software reviews, troubleshooting assistance, and operational security coordination.
Security Compliance Responsibilities
- Collect and index compliance evidence, maintaining a structured evidence library with retrieval discipline and naming standards.
- Track evidence freshness and coordinate recurring evidence pulls according to UNCOMN's operating cadence.
- Support control testing, including evidence completeness checks and internal sampling support.
- Manage audit logistics, including PBC lists, auditor request tracking, response coordination, and closure tracking.
- Maintain training and attestation evidence, including completion tracking and audit-ready packaging.
- Support POA&M closure by assembling closure evidence packages and validating closure completeness.
- Intake and normalize vendor evidence from MSP and MSSP providers to ensure it meets UNCOMN audit expectations.
Requirements
- 7+ years of combined education and professional experience in cybersecurity operations, security engineering, and compliance/audit support.
- Must be eligible to obtain a Secret clearance, granted by the US Government, which requires US citizenship. The government also uses 13 adjudicative guidelines to determine an individual's eligibility.
- Hands-on experience with SIEM, endpoint protection, firewall change review, incident response, and vulnerability remediation.
- Experience managing audit evidence, supporting control testing, and coordinating audit readiness activities.
- Working knowledge of CMMC (Final Rule), NIST SP 800-171/171A/172, and ISO/IEC 27001.
- Strong documentation and cross-functional collaboration skills.
- Relevant certifications such as Security+, CySA+, or Microsoft SC-200 preferred.
Benefits & conditions
Health insurance, 401(k) matching, Paid time off, Employee assistance program, Paid holidays, Benefits from day one, * Instant Flexible PTO: Enjoy flexible paid time off starting your very first day with us!
- Generous Holidays: Benefit from 7 paid holidays and up to 3 floating holidays annually.
- Immediate Health Coverage: Get access to comprehensive health benefits from day one.
- 401K Safe Harbor Match: Secure your future with our top-tier 401K matching program.
- Growth Opportunities: Advance your career with our training and education assistance programs.
- Free Employee Assistance Program (EAP): Access complimentary support services for you and your family.