SOC Analyst

Cogent Inc
Harrisburg, PA, United States
16 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Shift work
Job source

Tech stack

Cyber Security Information Systems Computer Networks Query Languages Monitoring of Systems Intrusion Detection and Prevention Python (Programming Language) Network Protocols Windows PowerShell ArcSight SIEM Tool Kusto Query Language Security Information and Event Management
+7 more
Scripting Mitre Att&ck QRadar Cybercrime Microsoft Sentinel Splunk SentinelOne Expertise

Job description

The SOC Analyst II is responsible for monitoring, detecting, analyzing, and responding to cybersecurity threats to protect the confidentiality, integrity, and availability of the organization’s information systems. This role performs security event triage, incident investigation, threat hunting, detection engineering, and continuous monitoring to identify and mitigate cyber threats while improving the organization’s overall security posture. The analyst works within a 24x7 Security Operations Center (SOC) environment and collaborates with incident response, engineering, and infrastructure teams to ensure timely threat detection and resolution., * Monitor enterprise networks, endpoints, and security tools to detect and respond to cybersecurity events and potential threats.

  • Perform security event triage and investigate alerts escalated within the Security Operations Center (SOC) to determine scope, root cause, and business impact.
  • Analyze security logs, endpoint telemetry, network traffic, and indicators of compromise (IOCs) to identify malicious activity.
  • Conduct proactive threat hunting activities to detect advanced threats and security anomalies.
  • Tune and optimize SIEM detection rules, correlation logic, and alerting mechanisms to improve detection accuracy and reduce false positives.
  • Document security incidents, investigations, findings, and remediation activities following established policies and procedures.
  • Develop, maintain, and enhance SOC playbooks, standard operating procedures (SOPs), and incident response documentation.
  • Monitor external threat intelligence sources and incorporate actionable intelligence into security monitoring and detection strategies.
  • Support incident response activities by assisting with containment, eradication, recovery, and post-incident analysis.
  • Participate in root cause analysis, lessons learned sessions, and continuous improvement initiatives.
  • Accurately capture, log, and track security events received through monitoring systems, email, chat, phone, and other communication channels.
  • Collaborate with cybersecurity, infrastructure, and engineering teams to strengthen security monitoring capabilities.
  • Support a 24x7x365 Security Operations Center by participating in rotating shifts, including nights, weekends, and holidays.

Requirements

  • Experience in a Security Operations Center (SOC) or cybersecurity monitoring environment.
  • Strong knowledge of security monitoring, incident response, threat detection, and security investigations.
  • Experience analyzing SIEM alerts, endpoint telemetry, network traffic, and system logs.
  • Knowledge of Indicators of Compromise (IOCs), attack techniques, and threat hunting methodologies.
  • Experience working with SIEM platforms and security monitoring tools.
  • Understanding of network protocols, operating systems, and cybersecurity fundamentals.
  • Experience creating queries, reports, or scripts using SIEM query languages or scripting tools.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Excellent verbal and written communication skills.
  • Ability to work independently while collaborating effectively within a team environment.

Preferred Skills

  • Experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, Elastic, ArcSight, or LogRhythm.
  • Knowledge of MITRE ATT&CK, NIST Cybersecurity Framework, and Cyber Kill Chain.
  • Experience with EDR/XDR solutions such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black.
  • Familiarity with threat intelligence platforms and IOC analysis.
  • Experience with scripting or automation using PowerShell, Python, or Kusto Query Language (KQL).
  • Industry certifications such as Security+, CySA+, GCIH, GCIA, SC-200, CISSP, or equivalent are a plus.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:23 min

Boosting security operations center productivity with intelligent data analysis

Chris Wysopal Chris Wysopal +2 · WWC 2024

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

1:23 min

Understanding the complexity of cybersecurity domains

Jennifer Reif · LIVE

Videos

See all

Related articles

See all