> Markdown version of [/jobs/ext/2072232-soc-threat-detection-incident-response-analyst](https://www.wearedevelopers.com/jobs/ext/2072232-soc-threat-detection-incident-response-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC THREAT DETECTION & INCIDENT RESPONSE ANALYST - **Company:** Technet, LLC - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Amazon Web Services, Audit Trail, Cloud Computing, Cloud Computing Security, Databases, Middleware, Event Logging, File Transfer, Identity and Access Management, Internet Information Services (IIS), Information Systems Security Architecture Professional, Log Analysis, Microsoft SQL Server, Open Web Application Security, Salesforce.Com, Security Information and Event Management, Data Streaming, Web Applications, Software Security, Amazon Virtual Private Cloud (VPC), Amazon Relational Database Service, Cybercrime, Data Management, Route53, Splunk, Event Viewer, Vulnerability Analysis - **Published:** August 15, 2026 - **Apply:** https://www.dice.com/job-detail/1202ddcb-92ca-496b-a489-fd1c2fab19fe ## About the Role * Experience: 3+ years of hands-on experience in a Security Operations Center (SOC), Threat Analysis, or Incident Response role. * Tooling Proficiency: Direct experience analyzing alerts and querying logs within CrowdStrike Falcon, Wazuh (or ELK/OpenSearch/Splunk SIEM), and AWS Security Hub / GuardDuty. * Cloud & Identity Threat Knowledge: Practical experience analyzing AWS CloudTrail logs, detecting IAM abuse patterns, credential spraying, and web application attack vectors (OWASP Top 10, AWS WAF rules). * Log Analysis Skills: Strong ability to inspect and analyze raw logs from Windows Event Viewer, IIS web servers, database audit logs (SQL Server), and API/MFT transactional logs. * Incident Response Execution: Understanding of formal incident response methodologies (containment, eradication, recovery) and playbook execution. * U.S. Data Residency Requirement: Must reside and work exclusively within the United States., * CompTIA CySA+, Security+, or GIAC Certified Incident Handler (GCIH) * GIAC Certified Enterprise Defender (GCED) or GIAC Cloud Forensics (GCFA) * Certified Information Systems Security Professional (CISSP) or CISM * AWS Certified Cloud Practitioner or AWS Certified Solutions Architect Associate * Prior experience in utility, public power, or critical infrastructure operations. ## Description Technet is seeking a SOC Threat Detection & Incident Response Analyst to provide active security monitoring, threat detection, incident triage, and response for a critical energy-sector utility billing and data management platform. In this role, you will be responsible for active triage and correlation across CrowdStrike Falcon, a centralized Wazuh SIEM, AWS-native security services (GuardDuty, Security Hub, WAF), and application middleware. You will execute incident response actions and proactive threat hunts in strict alignment with utility emergency operations and incident response frameworks (CEOP/CIRP). 2. Technical Stack & Systems Monitored * Detection & SIEM Tools: Wazuh SIEM Dashboard & Correlation Engine, CrowdStrike Falcon (Falcon Console, FDR / Streaming API Telemetry). * Cloud Security Telemetry: Amazon GuardDuty, AWS Security Hub, AWS WAF, AWS CloudTrail, VPC Flow Logs, Route 53 Resolver logs. * Application & Data Tiers: Amazon RDS SQL Server audit logs, Windows Event Logs / IIS web logs, Dell Boomi middleware logs, GoAnywhere MFT transfer logs, Salesforce CRM connector logs. * Posture & Vulnerability Feeds: Wazuh SCA (Security Configuration Assessment), AWS Systems Manager (SSM) vulnerability findings, Containerized Prowler daily compliance reports. * Operational Frameworks: SOC 2 Type II controls, NIST CSF, and NIST 800-53., * Active SOC Monitoring & Triage: Monitor cloud, endpoint, network, and application security alerts Monday through Friday (7:00 AM - 6:30 PM PST), adhering to strict SLAs ( 15 minutes for Critical severity; 1 hour for High severity). * Multi-Stage Threat Correlation: Correlate disparate signals across CrowdStrike Falcon endpoint detections, AWS GuardDuty anomalies, CloudTrail management events, IIS web server logs, and RDS SQL Server audit records to identify complete attack chains. * Threat Hunting: Conduct hypothesis-driven and intelligence-driven threat hunts focusing on cloud credential hijacking, IAM privilege escalation, impossible-travel anomalies, MFA bypass, and unauthorized data staging/exfiltration. * Integration Edge & File Transfer Monitoring: Perform targeted monitoring of GoAnywhere MFT, Dell Boomi, and external data exchanges (PG&E feeds) for anomalous file transfers, off-hours execution, or unauthorized outbound connections. * Incident Response & Containment: Execute response playbooks aligned with enterprise CEOP and CIRP frameworks. Perform host isolation recommendations, credential revocation coordination, and initial evidence preservation. * Vulnerability & Posture Prioritization: Review daily vulnerability scan outputs from Wazuh SCA/SSM and posture findings from Prowler; prioritize findings by business impact and exploitability, and track remediation with engineering teams. * Reporting & Governance: Assist in preparing monthly security posture reviews, threat intelligence summaries, and quarterly executive risk dashboards. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [Branch your database like your code: How schema changes and pull requests go hand in hand](https://www.wearedevelopers.com/videos/350-branch-your-database-like-your-code-how-schema-changes-and-pull-requests-go-hand-in-hand) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)