SOC Analyst

Arctiq, Inc.
Nashville, TN, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Shift work
Job source

Tech stack

Microsoft Windows Active Directory Amazon Web Services Microsoft Azure Cloud Computing Cyber Security Linux Intrusion Detection and Prevention Kusto Query Language Security Information and Event Management TCP/IP Mitre Att&ck

Job description

We are hiring multiple SOC Analysts at the Tier 1 and Tier 2 levels to staff our Day, Swing, and Night shifts. You will be a frontline defender for a diverse portfolio of clients - monitoring detections, triaging alerts, leading investigations, executing response playbooks, and continuously improving the way we detect and respond to threats.

This role is ideal for analytical, curious, and resilient practitioners who enjoy fast-paced work, want exposure to a broad range of environments and technologies, and care deeply about protecting customers.

Responsibilities:

  • Continuously monitor and triage alerts and detections across SIEM, EDR/XDR, identity, email, network, and cloud telemetry for our managed client base, applying severity classification and initial enrichment on every event you touch.
  • Investigate suspicious activity end-to-end - from validation and pivoting through to root-cause analysis - using knowledge of attacker tradecraft, the MITRE ATT&CK framework, and the cyber kill chain to reach confident, well-supported conclusions.
  • Execute documented response playbooks to contain threats, including isolating hosts, disabling compromised accounts, blocking indicators, resetting credentials, and coordinating handoffs with client and engineering teams.
  • Partner with Detection Engineering to reduce noise and false positives, and to propose, test, and deploy new analytics, automations, and SOAR playbooks that make the SOC faster and more accurate.
  • Maintain audit-grade documentation throughout every case, capturing notes, timelines, and customer-facing communications cleanly in the ticketing and case-management system.
  • Consistently meet triage, investigation, and notification SLAs while sustaining high accuracy, low false-positive rates, and strong client satisfaction across the portfolio.
  • Drive continuous improvement of the SOC by feeding lessons learned back into detections, playbooks, runbooks, and knowledge-base articles in partnership with SOC Leadership and Detection Engineering.
  • Operate on an assigned shift (Day, Swing, or Night) within a 24x7 rotation - including weekends and holidays as scheduled - and respond to on-call escalations when required.

Requirements

Do you have experience in Windows?, * One or more years in an IT security role or IT support role with significant security responsibilities.

  • Working knowledge of core security concepts: TCP/IP, common protocols, Windows and Linux fundamentals, Active Directory / Entra ID, cloud (Azure / AWS / GCP) basics, and common attacker techniques.
  • Familiarity with at least one SIEM and one EDR/XDR platform; comfortable writing or modifying basic queries (KQL, SPL, or similar).

  • Demonstrated ability in effective communication and collaborating in a diverse high-performance team environment a strong commitment to customer service.
  • Individuals will be required to submit to a background examination., Candidates must be legally authorized to work in the country where they reside. Arctiq does not sponsor work Visas at this time.

About the company

Arctiq is a leader in professional IT services and managed services across three core Centers of Excellence: Enterprise Security, Modern Infrastructure and Platform Engineering. Renowned for our ability to architect intelligence, we connect, protect, and transform organizations, empowering them to thrive in today’s digital landscape. Arctiq builds on decades of industry expertise and a customer-centric ethos to deliver exceptional value to clients across diverse industries.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC Europe 2026

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

14:14 min

Addressing audience inquiries on analytical implementation and career growth

Julian Joseph · LIVE

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters · WWC 2022

2:14 min

Securing analysis platforms via network access controls

Jennifer Reif · LIVE

Videos

See all

Related articles

See all