Security Operations Center (SOC) Analyst I

ASM
Boise, ID, United States
17 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Starter
Experience required
1 year minimum
Compensation
$60,000.0 - $86,000.0
Working hours
Regular working hours
Job source

Tech stack

Multitier Architecture Application Layers Microsoft Azure Cloud Computing Security Complex Networks CompTIA Security+ Cyber Security Intrusion Detection Systems Log Analysis Phishing Microsoft SharePoint Security Information and Event Management
+7 more
Data Logging QRadar Malware Firewalls (Computer Science) Information Technology Splunk Vulnerability Analysis

Job description

The Security Operations Center (SOC) Analyst I is a frontline cyber defender responsible for monitoring security tools and dashboards to identify indicators of compromise across networks, endpoints, and cloud-hosted systems in mission-critical environments. The role focuses on triaging and analyzing alerts from SIEM and other monitoring platforms, distinguishing true incidents from benign activity and escalating confirmed threats to senior analysts or incident responders. SOC Analyst I staff support basic threat detection, documentation of security events, and coordination with IT and security teams for initial containment, while contributing to tuning rules, improving playbooks, and maintaining awareness of common attack techniques and vulnerabilities., * p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Monitor SIEM platforms and log analysis tools to triage security alerts across network, system, and application layers, identifying potential indicators of compromise.

  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Investigate suspicious activity using data from firewalls, IDS/IPS, endpoint protection, and cloud security services to identify potential threats and determine whether escalation is warranted.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Apply standard incident response playbooks and procedures, including initial containment steps, evidence preservation, and effective handoff to Tier II or incident response teams.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Review vulnerability scanning outputs and apply basic risk prioritization concepts to recognize misconfigurations and exploitable weaknesses in enterprise environments.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Document security events and incidents with accurate case records and concise reports that support post-incident review and continuous improvement activities.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Follow security frameworks and best practices relevant to highly regulated government or enterprise environments, including access control, monitoring, and logging requirements for mission-critical systems.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Participate in rule tuning and playbook improvements, providing feedback on false positives, emerging patterns, and common attack vectors, malware behaviors, and phishing techniques., Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM’s overall compensation and benefits package for employees.

Requirements

  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Bachelor’s Degree in Computer Science, Information Assurance, Cybersecurity, or a related field, or equivalent relevant experience (aligned to Operations Security Planner I standard). Standard-Job-Titles-SharePoint-2-11.xlsx
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Typically 1-3 years of hands-on experience in IT support, networking, or cybersecurity operations roles, including exposure to security monitoring or incident response.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Proficiency with SIEM platforms and log analysis tools for monitoring and triaging security alerts across multiple layers (network, system, application).
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Ability to investigate suspicious activity using data from firewalls, IDS/IPS, endpoint protection, and cloud security services, with foundational knowledge of common attack vectors and malware behaviors.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Familiarity with basic incident response processes, including initial containment, evidence preservation, and structured escalation to Tier II or incident response teams.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> U.S. Citizenship required, with ability to satisfy background investigation requirements appropriate to a federal IT environment.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Strong written and verbal communication skills, with attention to detail in documenting incidents and maintaining accurate case records.

Preferred Qualifications

  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Experience with at least one enterprise SIEM (e.g., Splunk, QRadar, Azure Sentinel) and creation or tuning of correlation rules.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Foundational cybersecurity certification such as CompTIA Security+, CySA+, or equivalent vendor-neutral credential.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Exposure to 24x7 operations or shift-based monitoring environments supporting large, complex networks.
  • p]:pt-0 [&>p]:mb-2 [&>p]:my-0”> Familiarity with vulnerability scanning tools and outputs, and with standard security frameworks used in highly regulated government or enterprise environments., The physical requirements described in “Knowledge, Skills and Abilities” above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, “light office duties’ or “lifting up to 50 pounds” or “some travel” required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.

About the company

ASM Research, An Accenture Federal Services Company

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

52 sec

Defining application, pipeline, and security operations roles

Aarno Aukia · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

1:13 min

Structuring a comprehensive corporate security organization

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

Videos

See all

Related articles

See all