Cybersecurity Analyst - SOC Operations

Primoris Services Corporation
United States
13 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$110,000.0 - $120,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Active Directory User Authentication Microsoft Azure Bash Shell Business Systems Software as a Service Cloud Computing Security CompTIA Security+ Cyber Security Domain Name System (DNS) Monitoring of Systems
+22 more
Intrusion Detection and Prevention Python (Programming Language) Network Security Microsoft Security Essentials Network Monitoring Windows PowerShell Remote Access Technology Azure Active Directory Phishing Zero Trust Network Access Security Log Security Information and Event Management EndPointSecurity Scripting Cloud Platform System Firewalls (Computer Science) Azure Security Center Microsoft Sentinel ArcSight Event Correlation Splunk Security Orchestration, Automation & Response Vulnerability Analysis

Job description

The Cybersecurity Analyst - SOC Operations is responsible for monitoring, detecting, investigating, and responding to cybersecurity threats across the enterprise environment. This role serves as a key member of the Security Operations Center (SOC) and focuses on threat detection, incident response, endpoint security, identity threats, and security monitoring of enterprise infrastructure, cloud environments, and critical business systems.

The analyst will investigate security alerts, triage incidents, correlate threat intelligence, and collaborate with IT and infrastructure teams to contain and remediate cybersecurity risks. This position plays an operational role in maintaining enterprise security visibility and minimizing cyber risk exposure., Security Monitoring & Threat Detection

  • Monitor enterprise security tools and alerts for suspicious activity, malicious behavior, or policy violations.
  • Analyze and triage security events generated from:
  • SIEM platforms
  • Endpoint Detection & Response (EDR)
  • Email security platforms
  • Network monitoring tools
  • Identity and access monitoring solutions
  • Cloud security platforms
  • Investigate indicators of compromise (IOCs), anomalous behaviors, and suspicious user activity.
  • Correlate logs and events across multiple security systems to identify threats.
  • Escalate high-risk incidents according to playbooks and incident severity classifications.

Incident Response

  • Participate in cybersecurity incident response activities including:
  • Detection
  • Triage
  • Containment
  • Eradication
  • Recovery
  • Post-incident review
  • Investigate phishing, malware, ransomware, account compromise, insider threat, and unauthorized access incidents.
  • Document incident findings, root cause analysis, and remediation recommendations.
  • Support after-hours cybersecurity response activities when necessary.

Endpoint, Identity & Network Security

  • Monitor endpoint security posture and investigate endpoint-related threats.
  • Analyze authentication anomalies including:
  • Privileged account misuse
  • Impossible travel
  • MFA anomalies
  • Suspicious logins
  • Excessive failed authentication attempts
  • Support Zero Trust security initiatives through continuous monitoring of identity, device, and access risks.
  • Investigate unusual network behavior and lateral movement attempts.

Cloud Security Monitoring

  • Monitor cloud security events across Microsoft 365, Azure, SaaS platforms, and enterprise cloud services.
  • Investigate risky cloud behaviors, privilege escalation, abnormal sharing, and unauthorized access attempts.
  • Assist with remediation of cloud security findings and misconfigurations.

Vulnerability & Exposure Management Support

  • Review vulnerability scan results and assist with prioritization of remediation activities.
  • Validate remediation of critical vulnerabilities.
  • Monitor exposure trends and recurring weaknesses affecting enterprise systems.

Security Automation & Continuous Improvement

  • Assist in developing playbooks and incident response procedures.
  • Support SOAR workflows and automation initiatives.
  • Identify opportunities to improve detection coverage and operational efficiencies.
  • Contribute to lessons learned and continuous improvement activities., We are not accepting resumes from Third Party Recruiting Firms for this position. If you are an Agency or Search firm representative, contact the Primoris Talent Acquisition Manager directly for consideration. Primoris or its subsidiaries will not be responsible for any fees arising from the use of resumes and online response forms through this source. In addition, Primoris or its subsidiaries will not be responsible for any fees on unsolicited resumes that are submitted to any member of the Staffing or Operations team. Primoris has established an approved vendor program for this service and will only consider accepting submissions from those approved firms. For consideration in becoming an approved vendor, contact HR.

Requirements

  • 5+ years of Cybersecurity experience required
  • CrowdStrike Falcon experience required
  • Security Monitoring & Detection:
  • SIEM platforms such as Microsoft Sentinel, Splunk Enterprise Security, or similar
  • EDR/XDR solutions such as Microsoft Defender for Endpoint or comparable platforms
  • Security log analysis and event correlation
  • Identity & Access Security:
  • Identity monitoring in environments such as:
  • Microsoft Entra ID
  • Active Directory
  • Privileged Access Management systems
  • Authentication threat analysis
  • Network & Cloud Security:
  • Firewall, DNS, proxy, and network telemetry analysis
  • Experience with:
  • Zscaler
  • Microsoft security ecosystem
  • Cloud security monitoring tools
  • Familiarity with SaaS and remote-access security models
  • Automation & Response:
  • Experience with scripting (PowerShell, Python, or Bash preferred)
  • Familiarity with SOAR and security automation

Preferred Certifications:

Preferred certifications include:

  • CompTIA Security+
  • CompTIA CySA+
  • GCIH
  • AZ-500
  • CISSP (preferred for senior analyst level)

Benefits & conditions

  • 401k w/employer match
  • Health/Dental/Vision insurance plans
  • Paid time off
  • 10 paid holidays
  • Stock purchase plan

About the company

Primoris Renewable Energy provides the following compensation range and general description of other compensation and benefits that it in good faith believes it might pay and/or offer for this position. This compensation range is based on a full-time schedule. Primoris Renewable Energy reserves the right to ultimately pay more or less than the posted range and offer additional benefits and other compensation, depending on circumstances not related to an applicant’s sex or other status protected by local, state, or federal law., Primoris Services Corporation is a premier specialty contractor providing critical infrastructure services to the utility, energy, and renewables markets throughout the United States and Canada. Built on a foundation of trust, we deliver a range of engineering, construction, and maintenance services that power, connect, and enhance society. On projects spanning utility-scale solar, renewables, power delivery, communications, and transportation infrastructure, we offer unmatched value to our clients, a safe and entrepreneurial culture to our employees, and innovation and excellence to our communities. To learn more, visit and follow us on social media at @PrimorisServicesCorporation.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

Videos

See all

Related articles

See all