> Markdown version of [/jobs/ext/208843-soc-analyst](https://www.wearedevelopers.com/jobs/ext/208843-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC Analyst - **Company:** Arctiq, Inc. - **Location:** Nashville, TN, United States (Remote available) - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Amazon Web Services, Microsoft Azure, Cloud Computing, Cyber Security, Linux, Intrusion Detection and Prevention, Kusto Query Language, Security Information and Event Management, TCP/IP, Mitre Att&ck - **Published:** May 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=634302f8cedc9942 ## About the Role Do you have experience in Windows?, * One or more years in an IT security role or IT support role with significant security responsibilities. * Working knowledge of core security concepts: TCP/IP, common protocols, Windows and Linux fundamentals, Active Directory / Entra ID, cloud (Azure / AWS / GCP) basics, and common attacker techniques. * Familiarity with at least one SIEM and one EDR/XDR platform; comfortable writing or modifying basic queries (KQL, SPL, or similar). * Demonstrated ability in effective communication and collaborating in a diverse high-performance team environment a strong commitment to customer service. * Individuals will be required to submit to a background examination., Candidates must be legally authorized to work in the country where they reside. Arctiq does not sponsor work Visas at this time. ## Description We are hiring multiple SOC Analysts at the Tier 1 and Tier 2 levels to staff our Day, Swing, and Night shifts. You will be a frontline defender for a diverse portfolio of clients - monitoring detections, triaging alerts, leading investigations, executing response playbooks, and continuously improving the way we detect and respond to threats. This role is ideal for analytical, curious, and resilient practitioners who enjoy fast-paced work, want exposure to a broad range of environments and technologies, and care deeply about protecting customers. Responsibilities: * Continuously monitor and triage alerts and detections across SIEM, EDR/XDR, identity, email, network, and cloud telemetry for our managed client base, applying severity classification and initial enrichment on every event you touch. * Investigate suspicious activity end-to-end - from validation and pivoting through to root-cause analysis - using knowledge of attacker tradecraft, the MITRE ATT&CK framework, and the cyber kill chain to reach confident, well-supported conclusions. * Execute documented response playbooks to contain threats, including isolating hosts, disabling compromised accounts, blocking indicators, resetting credentials, and coordinating handoffs with client and engineering teams. * Partner with Detection Engineering to reduce noise and false positives, and to propose, test, and deploy new analytics, automations, and SOAR playbooks that make the SOC faster and more accurate. * Maintain audit-grade documentation throughout every case, capturing notes, timelines, and customer-facing communications cleanly in the ticketing and case-management system. * Consistently meet triage, investigation, and notification SLAs while sustaining high accuracy, low false-positive rates, and strong client satisfaction across the portfolio. * Drive continuous improvement of the SOC by feeding lessons learned back into detections, playbooks, runbooks, and knowledge-base articles in partnership with SOC Leadership and Detection Engineering. * Operate on an assigned shift (Day, Swing, or Night) within a 24x7 rotation - including weekends and holidays as scheduled - and respond to on-call escalations when required. ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)