> Markdown version of [/jobs/ext/252260-soc-analyst-l](https://www.wearedevelopers.com/jobs/ext/252260-soc-analyst-l). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC Analyst l - **Company:** Belcan - **Location:** Cincinnati, OH, United States - **Experience:** Experienced - **Salary:** $72,000.0 - $85,000.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Cyber Security, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Python (Programming Language), Log Analysis, Phishing, Security Information and Event Management, Malware, Cyber Threat Analysis, Cortex XSOAR Platform - **Published:** May 20, 2026 - **Apply:** https://belcanjobs.smartsearchonline.com/jobs_techservices/jobdetails.asp?job_number=365170 ## About the Role · 2 to 6 years of experience in security operations, incident response, SOC analysis, or related cybersecurity disciplines. · Experience with Securonix Security Analytics, Digital Guardian DLP, Palo Alto Prisma, Palo Alto XSIAM, and Palo Alto XSOAR. · Proficiency with Python automation and SIEM technologies. · Ability to analyze complex security events, correlate indicators, and support proactive threat detection. · Industry security certifications such as Security+, GSEC, CySA+, or equivalent are preferred. · Strong investigative, analytical, and incident response skills are essential for success in this role. · Ability to contribute to documentation, reporting, mentoring, and continuous improvement within the security operations environment. · Strong understanding of cloud risk management, compliance, and secure architecture principles is essential. · Ability to guide cloud security strategy, incident response, and cross-functional security enablement across the organization ## Description Description: A Threat Intel Analyst job in Blue Ash, Ohio is currently available at Belcan. To be considered for this role, you will have a minimum of three years of relevant experience. This position will be primarily responsible for maintaining an operating environment consisting of security technologies. You will work closely with other team members to continuously improve visibility, detect and prevent threats, and provide reporting data to protect Belcan customer IP, Belcan employee data, and support both IT and regulatory initiatives., · Perform advanced investigation and analysis of escalated security incidents from Tier 1 analysts, including complex malware, phishing, insider threats, and advanced persistent threats (APTs). · Lead and coordinate incident response efforts through all phases. · Utilize Security Information and Event Monitoring (SIEM) and UEBA tools to conduct in-depth log analysis, correlate events, and identify suspicious patterns or anomalies. · Proactively hunt for threats by identifying patterns and indicators of compromise (IOCs) using SIEM, EDR, and other tools. · Collaborate with engineering teams to tune and optimize security tools such as SIEM, EDR, and DLP to reduce false positives and improve detection capabilities. · Conduct forensic investigations, including file analysis, to determine the scope and impact of incidents. · Collaborate with the GRC team to prioritize and track resolution of vulnerabilities. · Create detailed incident reports, including analysis and recommendations. · Contribute to playbooks, processes, and knowledge base documentation. · Work closely with Tier 1 analysts, providing guidance and mentorship, and assisting with skill development and knowledge sharing. · Identify areas for security improvement and collaborate with cross-functional teams to enhance security posture. ## Related Videos - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Leveraging Large Language Models for Legacy Code Translation: Challenges and Solutions](https://www.wearedevelopers.com/videos/1157-leveraging-large-language-models-for-legacy-code-translation-challenges-and-solutions) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)