> Markdown version of [/jobs/ext/2198795-cybersecurity-analyst-soc-operations](https://www.wearedevelopers.com/jobs/ext/2198795-cybersecurity-analyst-soc-operations). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Analyst - SOC Operations - **Company:** Primoris Services Corporation - **Location:** United States - **Experience:** Expert - **Salary:** $110,000.0 - $120,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, User Authentication, Microsoft Azure, Bash Shell, Business Systems, Software as a Service, Cloud Computing Security, CompTIA Security+, Cyber Security, Domain Name System (DNS), Monitoring of Systems, Intrusion Detection and Prevention, Python (Programming Language), Network Security, Microsoft Security Essentials, Network Monitoring, Windows PowerShell, Remote Access Technology, Azure Active Directory, Phishing, Zero Trust Network Access, Security Log, Security Information and Event Management, EndPointSecurity, Scripting, Cloud Platform System, Firewalls (Computer Science), Azure Security Center, Microsoft Sentinel, ArcSight Event Correlation, Splunk, Security Orchestration, Automation & Response, Vulnerability Analysis - **Published:** August 23, 2026 - **Apply:** https://www.dice.com/job-detail/ee521d3e-0b88-4146-812e-4ff31f84da85 ## About the Role * 5+ years of Cybersecurity experience required * CrowdStrike Falcon experience required * Security Monitoring & Detection: * SIEM platforms such as Microsoft Sentinel, Splunk Enterprise Security, or similar * EDR/XDR solutions such as Microsoft Defender for Endpoint or comparable platforms * Security log analysis and event correlation * Identity & Access Security: * Identity monitoring in environments such as: + Microsoft Entra ID + Active Directory + Privileged Access Management systems * Authentication threat analysis * Network & Cloud Security: * Firewall, DNS, proxy, and network telemetry analysis * Experience with: + Zscaler + Microsoft security ecosystem + Cloud security monitoring tools * Familiarity with SaaS and remote-access security models * Automation & Response: * Experience with scripting (PowerShell, Python, or Bash preferred) * Familiarity with SOAR and security automation Preferred Certifications: Preferred certifications include: * CompTIA Security+ * CompTIA CySA+ * GCIH * AZ-500 * CISSP (preferred for senior analyst level) ## Description The Cybersecurity Analyst - SOC Operations is responsible for monitoring, detecting, investigating, and responding to cybersecurity threats across the enterprise environment. This role serves as a key member of the Security Operations Center (SOC) and focuses on threat detection, incident response, endpoint security, identity threats, and security monitoring of enterprise infrastructure, cloud environments, and critical business systems. The analyst will investigate security alerts, triage incidents, correlate threat intelligence, and collaborate with IT and infrastructure teams to contain and remediate cybersecurity risks. This position plays an operational role in maintaining enterprise security visibility and minimizing cyber risk exposure., Security Monitoring & Threat Detection * Monitor enterprise security tools and alerts for suspicious activity, malicious behavior, or policy violations. * Analyze and triage security events generated from: + SIEM platforms + Endpoint Detection & Response (EDR) + Email security platforms + Network monitoring tools + Identity and access monitoring solutions + Cloud security platforms * Investigate indicators of compromise (IOCs), anomalous behaviors, and suspicious user activity. * Correlate logs and events across multiple security systems to identify threats. * Escalate high-risk incidents according to playbooks and incident severity classifications. Incident Response * Participate in cybersecurity incident response activities including: + Detection + Triage + Containment + Eradication + Recovery + Post-incident review * Investigate phishing, malware, ransomware, account compromise, insider threat, and unauthorized access incidents. * Document incident findings, root cause analysis, and remediation recommendations. * Support after-hours cybersecurity response activities when necessary. Endpoint, Identity & Network Security * Monitor endpoint security posture and investigate endpoint-related threats. * Analyze authentication anomalies including: + Privileged account misuse + Impossible travel + MFA anomalies + Suspicious logins + Excessive failed authentication attempts * Support Zero Trust security initiatives through continuous monitoring of identity, device, and access risks. * Investigate unusual network behavior and lateral movement attempts. Cloud Security Monitoring * Monitor cloud security events across Microsoft 365, Azure, SaaS platforms, and enterprise cloud services. * Investigate risky cloud behaviors, privilege escalation, abnormal sharing, and unauthorized access attempts. * Assist with remediation of cloud security findings and misconfigurations. Vulnerability & Exposure Management Support * Review vulnerability scan results and assist with prioritization of remediation activities. * Validate remediation of critical vulnerabilities. * Monitor exposure trends and recurring weaknesses affecting enterprise systems. Security Automation & Continuous Improvement * Assist in developing playbooks and incident response procedures. * Support SOAR workflows and automation initiatives. * Identify opportunities to improve detection coverage and operational efficiencies. * Contribute to lessons learned and continuous improvement activities., We are not accepting resumes from Third Party Recruiting Firms for this position. If you are an Agency or Search firm representative, contact the Primoris Talent Acquisition Manager directly for consideration. Primoris or its subsidiaries will not be responsible for any fees arising from the use of resumes and online response forms through this source. In addition, Primoris or its subsidiaries will not be responsible for any fees on unsolicited resumes that are submitted to any member of the Staffing or Operations team. Primoris has established an approved vendor program for this service and will only consider accepting submissions from those approved firms. For consideration in becoming an approved vendor, contact HR. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)