SOC Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+3 more
Job description
We are looking for a SOC Analyst to join our team. You will be the consistent, accountable owner of alert triage during coverage hours - bringing the speed, rigor, and communication discipline that transforms alert handling from a best-effort scramble into a reliable, measurable function.
This is not a detection engineering or research role. Your deepest strength is triage: prioritizing fast, distinguishing signal from noise, and escalating with the context that lets engineers act immediately rather than re-investigate from scratch. That said, you operate with a continuous improvement mindset - feeding a structured tuning loop with the SOC Engineer and proposing runbook fixes when the playbook doesnât match reality.
What Youâll Do
- Alert Triage Own the queue during coverage hours. Prioritize and disposition alerts accurately and fast - high-severity alerts acknowledged within 15 minutes, all alerts dispositioned within SLA. Know the difference between a true positive and noise, and act accordingly without waiting to be told.
- Log & Threat Analysis Pivot across cloud, identity, and endpoint log sources to build a clear timeline when an alert warrants deeper investigation. Use MITRE ATT&CK as a reference frame to understand what youâre looking at and what it means in context.
- Incident Escalation & Communication Escalate incidents with complete, actionable context - severity reasoning, timeline, affected systems, and recommended next steps. Write clearly in English. Engineers receiving your escalations should be able to act without asking follow-up questions.
- Runbook Discipline & Improvement Follow runbooks rigorously. When a runbook falls short - wrong steps, missing cases, outdated assumptions - flag it and propose a fix. Runbooks improve because analysts use them critically, not just obediently.
- Tuning Feedback Loop Run a weekly feedback cycle with the SOC Engineer. Report false positives, patterns in noise, and cases where detection logic needs adjustment. Improve signal quality over time rather than just processing the same noise on repeat.
- Audit Readiness Keep monitoring and response evidence current and organized for SOC 2, ISO 27001, and customer incident response commitments. Triage work that isnât documented doesnât exist for audit purposes - make sure yours does., We take full responsibility for our work, outcomes, and team success. No excuses, no blame-shifting - if something needs fixing, we own it and make it better. This means stepping up, even when itâs not âyour job.â If a ball is dropped, we pick it up. If a customer is unhappy, we fix it. If a process is broken, we redesign it. We donât wait for someone else to solve it - we lead with accountability and expect the same from those around us.
Craftsmanship
Putting care and intention into every task, striving for excellence, and taking deep ownership of the quality and outcome of your work. Craftsmanship means never settling for âjust fine.â We sweat the details because details compound. Whether itâs a product feature, an internal doc, or a sales call - we treat it as a reflection of our standards. We aim to deliver jaw-dropping customer experiences by being curious, meticulous, and proud of what we build - even when nobodyâs watching.
We are âmajosâ Be friendly & have fun with your coworkers. Always be genuine & honest, but kind. âMajoâ is our way of saying: be a good human. Be approachable, helpful, and warm. Weâre building something ambitious, and itâs easier (and more fun) when we enjoy the ride together. We give feedback with kindness, challenge each other with respect, and celebrate wins together without ego.
Urgency with Focus Create the highest impact in the shortest amount of time. Move fast, but in the right direction. We operate with speed because time is our most limited resource. But speed without focus is chaos. We prioritize ruthlessly, act decisively, and stay aligned. We aim for high leverage: the biggest results from the simplest, smartest actions. Weâre running a high-speed marathon - not a sprint with no strategy.
Talent Density and Meritocracy Hire only people who can raise the average; âexceptional performance is the passing grade.â Ability trumps seniority. We believe the best teams are built on talent density - every hire should raise the bar. We reward contribution, not titles or tenure. We give ownership to those who earn it, and we all hold each other to a high standard. A-players want to work with other A-players - thatâs how we win.
Requirements
- 2-3 years as a SOC analyst or in a blue team / detection and response role.
- Hands-on alert triage experience with a SIEM and an EDR - investigation, disposition, and escalation.
- Log analysis across cloud, identity, and endpoint sources.
- Working knowledge of MITRE ATT&CK and common attack patterns.
- Clear written incident notes and escalations in English (B2+).
- Comfortable operating on a coverage-hours rotation.
Nice to Have
- Cloud console familiarity with AWS, Azure, or GCP.
- Scripting basics in Python or Bash.
- Phishing and email threat analysis experience.
- Certifications: BTL1, GCIH, Security+, or CySA+.
- Exposure to detection tuning or writing simple detection rules.
- Prior experience at a SaaS or tech startup.
Benefits & conditions
- Join a world-class team of engineers and builders.
- Backed by top investors including a16z, Y Combinator, Base10, Prysm Capital and Eurazeo.
- Have ownership and autonomy of projects and are encouraged to ship.
- Comprehensive Benefits including healthcare, dental, vision coverage.
- Competitive salary + equity in a high-growth startup.
About the company
HappyRobot is the infrastructure for enterprises to build and orchestrate AI workforces. Our AI workers donât just communicate through voice and email - they make decisions, take action, and run operations autonomously across entire enterprise systems. Born in Y Combinator (S23) and backed by a16z, Base10, Prysm Capital and Eurazeo with over $150M raised, we power critical operations for global enterprises worldwide.
Our platform is battle-tested in the most demanding environments, where AI has real consequences. We started in logistics, built our own voice stack, models, and orchestration layer from the ground up, and are now bringing that infrastructure to every enterprise that runs the real economy. Learn more about our vision in our manifesto.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role â technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Data Analyst Salary in the UK
Dev Digest 131 - AI'm not sure about OSS
Dev Digest 134 - Where pixels sing?
Dev Digest 138 - Are you secure about this?