> Markdown version of [/jobs/ext/3558571-information-security-analyst-soc](https://www.wearedevelopers.com/jobs/ext/3558571-information-security-analyst-soc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst (SOC) - **Company:** Kforce Inc. - **Location:** Commerce, CA, United States - **Contract:** Internship / Graduate position - **Skills:** JIRA, CompTIA Security+, Cyber Security, Identity and Access Management, Information Technology Operations, Python (Programming Language), Windows PowerShell, Role-Based Access Control, Azure Active Directory, Anti-Phishing, Web Application Security, Security Information and Event Management, Software Vulnerability Management, Scripting, Okta, QRadar, Information Technology, Nessus, Microsoft Sentinel, SailPoint, Splunk, Qualys, Servicenow, Vulnerability Analysis - **Published:** October 2, 2026 - **Apply:** https://www.dice.com/job-detail/d950e670-04bf-4de8-b6c7-52301244b3ff ## About the Role * Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field, or equivalent practical experience * Must have experience with incident investigation and response * Experience in information security, IT operations, or helpdesk/service desk role * Hands-on experience (including internships or coursework) with an IAM management tool (e.g., SailPoint, Okta, Saviynt, Microsoft Entra ID/Azure AD, or similar) * Basic understanding of user access recertification/attestation processes * Basic understanding of email header structure and ability to identify indicators of phishing or spoofing * Basic understanding of vulnerability management concepts and exposure to vulnerability scanning tools (e.g., Tenable/Nessus, Qualys, Rapid7) is a plus * Exposure to security event monitoring or SIEM tools (e.g., Splunk, Microsoft Sentinel, QRadar) is a plus * Familiarity with URL/web filtering concepts and tools (e.g., proxy or secure web gateway solutions) * Familiarity with EDR/XDR tools * Strong attention to detail and ability to follow documented procedures accurately * Good written and verbal communication skills for ticket documentation and cross-team coordination * Ability to prioritize and manage multiple tickets/requests in a fast-paced environment Preferred Qualifications: * Industry certification such as CompTIA Security+, or equivalent (or actively pursuing) * Familiarity with ITSM/ticketing platforms (e.g., ServiceNow, Jira Service Management) * Basic scripting or automation exposure (e.g., PowerShell, Python) for repetitive task efficiency * Understanding of least-privilege and role-based access control (RBAC) principles ## Description A client with Kforce is seeking an Information Security Analyst (SOC) to join their team. This is a hybrid position in Commerce, CA., The Information Security Analyst is a position on the Information Security team, responsible for supporting day-to-day security operations. This role supports Identity and Access Management actions, user access recertification, security event monitoring, vulnerability management, and initial triage of security incidents, including email header analysis for phishing and spoofing investigations. The Analyst works under the guidance of senior analysts and the Cyber Security Services Manager, following established procedures and escalating complex or high-risk issues as needed., * Support periodic user access recertification/attestation campaigns, working with system and business owners to validate and remove inappropriate access * Maintain accurate records of access changes to support audit and compliance requirements * Monitor security event alerts (SIEM or equivalent tools) for anomalies, policy violations, and potential threats * Perform initial triage and analysis of security events, escalating confirmed or suspected incidents per the incident response process * Conduct email header analysis to investigate suspicious, phishing, or spoofed emails, and take appropriate response actions (e.g., blocking senders, quarantining messages, user notification) * Assist in documenting incident timelines, actions taken, and lessons learned * Run scheduled vulnerability scans and assist in maintaining scan schedules and scope lists * Help prepare and distribute routine vulnerability reports for IT and application owners * Track open vulnerabilities and follow up with owners to confirm remediation status until closure * Escalate overdue or high-severity findings to senior analysts or the manager