Tier 1 - SOC Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
- Monitor and triage. Work the alert queue across client environments during your shift in our 24x7x365 SOC - validating detections, separating true positives from noise, and pulling the thread when something looks wrong.
- Investigate. Use MITRE ATT&CK and Cyber Kill Chain analysis to understand what an attacker was attempting, how far they got, and what else may have been touched.
- Respond. Follow established playbooks to contain, remediate, or escalate - and know when the playbook doesnât cover what youâre seeing.
- Write it down clearly. Deliver investigation reports to clients through our service management system. Clear writing is a core skill here, not a nice-to-have.
- Talk to clients. Stay engaged through the lifecycle of escalated investigations, including calls with client IT and leadership.
- Hand off cleanly. Participate in shift handovers, team huddles, and internal reviews so nothing gets dropped between shifts.
- Keep sharpening. Stay current on emerging vulnerabilities, threat actor tradecraft, and attack trends - on paid time, with training we sponsor.
Your first 90 days
- Days 1-30: Onboarding and tooling. Youâll shadow experienced analysts, learn our detection stack and playbooks, and start working alerts with a senior analyst reviewing your calls.
- Days 31-60: Youâre running your own queue during your shift, writing client-facing reports, and escalating with confidence.
- Days 61-90: Youâre a full shift contributor - handling escalations independently, joining client calls, and starting to spot detection tuning opportunities., * Technical conversation with a senior SOC analyst - a discussion about how you think through an investigation, not a trivia quiz
- Final conversation with SOC leadership
- Offer
We aim to move from application to offer in under three weeks and to give every candidate who reaches the technical conversation a real answer either way.
Requirements
- Foundational understanding of networking and endpoint security - how systems talk, what normal looks like, and how attackers abuse both
- Familiarity with MITRE ATT&CK and the Cyber Kill Chain
- Strong written communication - you can explain a technical finding to a non-technical business owner without dumbing it down or drowning them
- The judgment to know when something is off, and the persistence to keep digging
- A reliable home internet connection and a private, quiet workspace suitable for handling sensitive client data
- Willingness to work rotating shifts, including nights, weekends, and holidays
- Ability to pass a background check
How you got there is up to you. A cybersecurity degree, a Security+ or CySA+, a home lab, a help desk background, military experience, or a bootcamp plus real self-study all count. We care about what you can do, not which box you checked.
Bonus points for:
- Hands-on or coursework exposure to a SIEM - Securonix, Microsoft Sentinel, CrowdStrike, Splunk, or similar
- Hands-on or coursework exposure to an EDR platform - SentinelOne, CrowdStrike, Huntress, Carbon Black, Defender, or similar
- Certifications such as Security+, CySA+, BTL1, GCIH, or CEH
- Scripting for repetitive work (PowerShell, Python, KQL)
- Prior MSP or MSSP experience - you already know what juggling multiple client environments feels like
Benefits & conditions
Pulled from the full job description Paid training Paid time off Paid holidays Flexible schedule
Full job description
Tier 1 SOC Analyst
Location: Fully Remote (U.S.) Type: Full-time, hourly Pay: $20 - $25/hour + shift differential for nights and weekends Schedule: Rotating 8-hour shifts, days or nights
Real security work, from day one
Most entry-level SOC jobs are alert factories: close the ticket, move to the next one, learn nothing.
Thatâs not how we run our SOC. At VDA Labs youâll investigate alerts across a portfolio of real client environments - manufacturers, healthcare practices, school districts, casinos, financial firms, using enterprise tooling like Securonix, SentinelOne, Crowdstrike and Huntress. Youâll map what you find to MITRE ATT&CK, write the investigation up in your own words, and talk directly to the client about what happened and what to do next.
If youâre coming out of a cyber program, a help desk role, or a career change and you want the reps that actually build an analyst, this is the seat., * Flexible schedule
About the company
Shift preference is discussed during the interview. We do our best to match preference, and shift changes open up as the team grows.
What we provide
- Fully remote work - our SOC has been 100% remote since day one, not as a pandemic holdover
- All equipment provided
- [PTO and paid holidays]
- Direct access to senior analysts, threat hunters, and our IR team - not a ticket queue between you and expertise
Where this goes
Tier 1 is the entry point, not the ceiling. Analysts here have moved into Tier 2 investigation, threat hunting, digital forensics and incident response, detection engineering, and client-facing security consulting. We promote from within and weâd rather grow the analyst who already knows our clients than hire around them.
About VDA Labs
VDA Labs is a Michigan-based cybersecurity firm helping organizations of all sizes monitor, detect, and respond to cyber threats. We deliver Managed Detection and Response, Threat Hunting, Digital Risk Protection, and Incident Response - tailored to each clientâs actual risk profile rather than a one-size-fits-all package.
Our clients range from regional manufacturers and healthcare practices to school districts, tribal gaming operations, and financial institutions. That variety means the alerts you work are genuinely different week to week.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role â technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 134 - Where pixels sing?
Walking Into The Era of Supply Chain Risks
Dev Digest 191: Malware interviews, EU â¤ď¸ Open Source and Skilled Agents