> Markdown version of [/jobs/ext/1204626-security-operations-center-soc-analyst-siem-splunk](https://www.wearedevelopers.com/jobs/ext/1204626-security-operations-center-soc-analyst-siem-splunk). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Operations Center (SOC) Analyst - SIEM / Splunk - **Company:** Wintrio Llc - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Amazon Web Services, JIRA, Bash Shell, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Linux, Identity and Access Management, Intrusion Detection and Prevention, Intrusion Detection Systems, Virtual Private Networks (VPN), Python (Programming Language), Network Security, Log Analysis, Microsoft Security Essentials, NetFlow, Network Monitoring, Windows PowerShell, Azure Active Directory, Cloud Services, Security Information and Event Management, Wireshark, EndPointSecurity, Enterprise Software Applications, QRadar, Firewalls (Computer Science), Information Technology, Cybercrime, Microsoft Sentinel, Cloudwatch, Splunk, SentinelOne Expertise, Elk Stack, Servicenow, Vulnerability Analysis - **Published:** July 8, 2026 - **Apply:** https://www.wintrio.com/careers/security-operations-center-soc-analyst-siem-splunk/ ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field, or equivalent professional experience. * Minimum three (3) years of experience supporting cybersecurity operations, SOC activities, incident response, threat monitoring, or SIEM administration. * Hands-on experience using Splunk or comparable SIEM platforms. * Strong understanding of incident response processes, threat detection methodologies, log analysis, and alert triage. * Experience analyzing endpoint, network, identity, application, and cloud security logs. * Familiarity with Federal cybersecurity requirements, continuous monitoring programs, and compliance reporting. * Strong written and verbal communication skills. * Strong analytical, investigative, and problem-solving abilities. Technical Areas Security Operations & Incident Response * Security Event Monitoring * Alert Triage * Incident Investigation, * AWS Security Monitoring * Azure Security Monitoring * Identity Security Monitoring * Network Security Monitoring * Endpoint Security Monitoring Tools & Platforms SIEM Platforms * Splunk Enterprise * Splunk Enterprise Security * ELK Stack * Microsoft Sentinel * IBM QRadar Endpoint & EDR Platforms * CrowdStrike * Microsoft Defender * Carbon Black * Trellix * SentinelOne Network Security Tools * Firewalls * IDS/IPS Platforms * VPN Monitoring * NetFlow Analysis * Wireshark Identity & Access Security * Active Directory * Microsoft Entra ID (Azure AD) * Privileged Access Monitoring Cloud Security Monitoring * AWS CloudTrail * Amazon GuardDuty * AWS CloudWatch * Azure Monitor * Microsoft Defender for Cloud Incident Management & Collaboration * ServiceNow * JIRA * SOAR Platforms * Case Management Systems Scripting & Automation * Python * PowerShell * Bash Preferred Certifications * CompTIA Security+ * CompTIA CySA+ * Splunk Core Certified User * Splunk Core Certified Power User * Splunk Enterprise Security Certified Administrator * GIAC Certified Incident Handler (GCIH) * GIAC Security Essentials (GSEC) * Certified Ethical Hacker (CEH) * Microsoft Security Operations Analyst Associate Preferred Qualifications * Experience supporting Federal SOC, continuous monitoring, or incident response programs. * Experience creating Splunk dashboards, alerts, correlation searches, and executive-level reporting. * Experience supporting SOAR automation initiatives, threat hunting programs, or detection engineering activities. * Experience supporting cloud-hosted or hybrid technology environments. * Familiarity with NIST SP 800-53, NIST SP 800-61, FISMA, DHS CDM, and FedRAMP requirements. * Experience supporting enterprise cybersecurity operations centers. ## Description WINTrio LLC is seeking a Security Operations Center (SOC) Analyst with experience supporting Security Information and Event Management (SIEM) platforms, particularly Splunk, within Federal cybersecurity environments. This role is responsible for monitoring security events, investigating alerts, supporting incident response activities, conducting threat analysis, and enhancing operational visibility across enterprise systems. The successful candidate will help protect Federal environments by identifying suspicious activity, responding to security incidents, supporting continuous monitoring initiatives, and improving detection capabilities across cloud, network, application, and endpoint environments. The ideal candidate possesses strong analytical skills, experience working in a SOC or cybersecurity operations environment, and the ability to investigate and respond to security events in accordance with Federal cybersecurity requirements. Job Responsibilities * Monitor security alerts, events, and indicators using Splunk, SIEM dashboards, endpoint security platforms, network monitoring tools, and cloud security services. * Triage, investigate, document, and escalate security incidents based on severity, risk, mission impact, and established procedures. * Correlate security events across firewalls, endpoints, identity systems, vulnerability scanners, applications, and cloud platforms. * Develop, maintain, and refine Splunk searches, alerts, dashboards, reports, and correlation rules. * Support incident response activities, including containment, eradication, recovery, evidence collection, and after-action reporting. * Analyze logs from Windows, Linux, Active Directory, Azure AD/Entra ID, cloud services, firewalls, IDS/IPS solutions, endpoint detection platforms, and enterprise applications. * Support continuous monitoring, threat hunting, insider threat investigations, and suspicious activity detection efforts. * Document incidents, findings, timelines, remediation actions, and lessons learned using ServiceNow, JIRA, or similar tracking systems. * Support reporting activities aligned with Federal cybersecurity requirements, SLAs, compliance mandates, and incident response procedures. * Assist with SOC process improvement initiatives, playbook development, detection engineering, and workflow automation efforts. * Collaborate with cybersecurity, infrastructure, cloud, and application teams to strengthen organizational security posture. ## Related Videos - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Integrate your Cognitive Assistant with 3rd-party DBs and software](https://www.wearedevelopers.com/videos/249-integrate-your-cognitive-assistant-with-3rd-party-dbs-and-software) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)