> Markdown version of [/jobs/ext/1450054-security-operations-center-soc-analyst-i](https://www.wearedevelopers.com/jobs/ext/1450054-security-operations-center-soc-analyst-i). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Operations Center (SOC) Analyst I - **Company:** ASM - **Location:** Charleston, WV, United States - **Experience:** Starter - **Salary:** $60,000.0 - $86,000.0 - **Contract:** Permanent contract - **Skills:** Multitier Architecture, Application Layers, Microsoft Azure, Cloud Computing Security, CompTIA Security+, Cyber Security, Intrusion Detection Systems, Log Analysis, Phishing, Microsoft SharePoint, Security Information and Event Management, Data Logging, QRadar, Malware, Firewalls (Computer Science), Information Technology, Splunk, Vulnerability Analysis - **Published:** July 26, 2026 - **Apply:** https://www.juju.com/job/00000000gjmbvc ## About the Role + p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Bachelor's Degree in Computer Science, Information Assurance, Cybersecurity, or a related field, or equivalent relevant experience (aligned to Operations Security Planner I standard). Standard-Job-Titles-SharePoint-2-11.xlsx + p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Typically 1-3 years of hands-on experience in IT support, networking, or cybersecurity operations roles, including exposure to security monitoring or incident response. + p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Proficiency with SIEM platforms and log analysis tools for monitoring and triaging security alerts across multiple layers (network, system, application). + p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Ability to investigate suspicious activity using data from firewalls, IDS/IPS, endpoint protection, and cloud security services, with foundational knowledge of common attack vectors and malware behaviors. + p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Familiarity with basic incident response processes, including initial containment, evidence preservation, and structured escalation to Tier II or incident response teams. + p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> U.S. Citizenship required, with ability to satisfy background investigation requirements appropriate to a federal IT environment. + p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Strong written and verbal communication skills, with attention to detail in documenting incidents and maintaining accurate case records. Preferred Qualifications + p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Experience with at least one enterprise SIEM (e.g., Splunk, QRadar, Azure Sentinel) and creation or tuning of correlation rules. + p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Foundational cybersecurity certification such as CompTIA Security+, CySA+, or equivalent vendor-neutral credential., The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions. ## Description The Security Operations Center (SOC) Analyst I is a frontline cyber defender responsible for monitoring security tools and dashboards to identify indicators of compromise across networks, endpoints, and cloud-hosted systems in mission-critical environments. The role focuses on triaging and analyzing alerts from SIEM and other monitoring platforms, distinguishing true incidents from benign activity and escalating confirmed threats to senior analysts or incident responders. SOC Analyst I staff support basic threat detection, documentation of security events, and coordination with IT and security teams for initial containment, while contributing to tuning rules, improving playbooks, and maintaining awareness of common attack techniques and vulnerabilities., + p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Monitor SIEM platforms and log analysis tools to triage security alerts across network, system, and application layers, identifying potential indicators of compromise. + p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Investigate suspicious activity using data from firewalls, IDS/IPS, endpoint protection, and cloud security services to identify potential threats and determine whether escalation is warranted. + p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Apply standard incident response playbooks and procedures, including initial containment steps, evidence preservation, and effective handoff to Tier II or incident response teams. + p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Review vulnerability scanning outputs and apply basic risk prioritization concepts to recognize misconfigurations and exploitable weaknesses in enterprise environments. + p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Document security events and incidents with accurate case records and concise reports that support post-incident review and continuous improvement activities. + p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Follow security frameworks and best practices relevant to highly regulated government or enterprise environments, including access control, monitoring, and logging requirements for mission-critical systems. + p]:pt-0 [&>p]:mb-2 [&>p]:my-0"> Participate in rule tuning and playbook improvements, providing feedback on false positives, emerging patterns, and common attack vectors, malware behaviors, and phishing techniques., Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees. ## Related Videos - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) - [WeAreDevelopers LIVE - Yes, CSS Can Do That!](https://www.wearedevelopers.com/videos/1819-wearedevelopers-live-yes-css-can-do-that) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)