Security Operations Center Analyst

DevCare Solutions
Harrisburg, PA, United States
18 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$64,480.0 - $72,800.0
Working hours
Shift work
Job source

Tech stack

Border Gateway Protocol Cisco PIX CompTIA Security+ Cyber Security Computer Networks Dynamic Host Configuration Protocol Digital Assets Domain Name System (DNS) Identity and Access Management Internet Protocol Security (IP SEC) Intrusion Detection Systems Virtual Private Networks (VPN)
+16 more
Log Analysis Networking Basics Routing Network Protocols Open Shortest Path First (OSPF) Remote Access Technology Security Software Security Information and Event Management TCP/IP Software Vulnerability Management Wide Area Networks Identity Services Engine Network Support Splunk Cisco Vulnerability Analysis

Job description

We are seeking a highly motivated and detail-oriented Tier 1 SOC Analyst to join our dynamic cybersecurity team. In this role, you will serve as the frontline defender, monitoring security events and alerts across our IT infrastructure to identify potential threats and vulnerabilities. Your proactive approach will help safeguard our network environment by analyzing security data, escalating incidents, and supporting incident response efforts. This position offers an exciting opportunity to develop your cybersecurity expertise while contributing to the protection of critical digital assets in a fast-paced environment., * Monitor and analyze security alerts generated by SIEM (Security Information and Event Management) systems to detect potential security incidents.

  • Conduct initial triage of security events, including intrusion detection system (IDS) alerts, firewall logs, and endpoint detection and response (EDR) notifications.
  • Escalate confirmed or suspected security incidents to senior analysts or incident response teams for further investigation.
  • Maintain accurate documentation of security events, actions taken, and incident reports in accordance with security policies.
  • Support vulnerability management activities by assisting in vulnerability assessments and security risk investigations.
  • Collaborate with network support teams to review network traffic patterns involving LAN, WAN, IPsec VPNs, and routing protocols such as OSPF or BGP.
  • Assist in maintaining security system configurations, including firewalls like Cisco ASA, Cisco ISE for identity management, and system hardening procedures based on ISO 27001 standards.

Requirements

  • Basic understanding of computer networking concepts including LAN, WAN, TCP/IP, DNS, DHCP, and network protocols.
  • Familiarity with cybersecurity tools such as SIEM platforms (e.g., Splunk), IDS/IPS systems, and endpoint detection solutions.
  • Knowledge of security frameworks like ISO 27001/27000 series standards and NIST cybersecurity standards.
  • Experience with firewall management (Cisco ASA), VPN technologies (IPsec), and network support functions.
  • Ability to analyze logs for threat detection & response using log analysis techniques and threat intelligence sources.
  • Strong problem-solving skills with a focus on security analysis and incident recovery procedures.
  • Excellent communication skills to document findings clearly and escalate issues effectively.
  • Relevant certifications such as CompTIA Security+, Cisco CCNA Security or equivalent are preferred but not mandatory.

Join us to be part of a forward-thinking team dedicated to protecting our digital landscape! We value proactive individuals eager to grow their cybersecurity expertise while making a tangible impact on organizational security posture through vigilant monitoring, threat detection, and incident management aligned with industry best practices.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters · WWC 2022

Videos

See all

Related articles

See all