> Markdown version of [/jobs/ext/739719-soc-analyst-i](https://www.wearedevelopers.com/jobs/ext/739719-soc-analyst-i). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC Analyst I - **Company:** Apollo - **Location:** United States (Remote available) - **Experience:** Starter - **Salary:** $50,000.0 - $80,000.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Cyber Security, Computer Programming, Computer Networks, Digital Assets, Internet Information Services (IIS), Intrusion Detection Systems, Virtual Private Networks (VPN), Python (Programming Language), Network Architecture, Network Segmentation, Network Protocols, Windows PowerShell, Security Information and Event Management, Scripting, Mitre Att&ck, Cyber Threat Analysis, Firewalls (Computer Science), Fortinet, Splunk, SentinelOne Expertise, Cisco - **Published:** June 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=0ae6fae54a6fad8e ## About the Role Do you have experience in Network protocols?, * Required + Basic understanding of networking concepts, protocols, and security principles. + Familiarity with common security tools and technologies (e.g., firewalls, IDS/IPS, SIEM). + Strong analytical and problem-solving skills. + Excellent written and verbal communication skills. + Ability to work in a fast-paced environment and handle multiple priorities. + Basic scripting or programming skills (e.g., Python, PowerShell). + Ability to work in shifts, including swings, nights, weekends, and holidays. * Preferred + Experience with CrowdStrike, Sophos, and/or SentinelOne platforms. + Familiarity with one or more SIEM platforms (e.g., Stellar, Splunk, Exabeam, LogRhythm, Elastic). + Experience with cloud security concepts and technologies. + Experience with threat intelligence platforms and processes. + Familiarity with the MITRE ATT&CK framework. + Familiarity with network infrastructure and security concepts (firewalls, VPNs, network segmentation, IDS/IPS). + Experience with enterprise firewall platforms (e.g., Sophos, Fortinet, Cisco, Check Point). ## Description Apollo's SOC Analyst I is a member of the Security Operations Center team responsible for monitoring and detecting threats and cybersecurity attacks across our clients' networks and systems. The SOC Analyst I monitors, analyzes, and responds to security events and alerts, working collaboratively with the team to protect client digital assets and maintain a strong security posture., * Monitor security events and alerts using SIEM tools and other security technologies. * Analyze and triage security alerts to determine severity and potential impact. * Perform initial incident response activities and escalate issues when necessary. * Document and track security incidents and their resolutions. * Assist in creating and maintaining security documentation and procedures. * Contribute to the development and improvement of security metrics and reporting. * Collaborate with other team members and departments to address security concerns. * Partner with SOC Analyst II to develop and refine SIEM correlation rules. * Stay informed about emerging threats and security trends., * At 30 days: + Complete onboarding to Apollo's SOC tool stack + Shadow senior analysts across monitoring shifts to internalize Apollo's alert triage logic, escalation thresholds, severity classifications, and incident documentation standards before owning work independently + Begin monitoring and triaging low-complexity alerts under guidance * Within 90 days: + Monitor and triage security alerts independently during assigned shifts - assessing severity, performing initial incident response activities, and escalating appropriately without needing to be prompted + Produce clean, accurate incident documentation consistently - every event tracked, every resolution recorded, in a format that's useful to the next analyst who picks it up + Demonstrate growing familiarity with the MITRE ATT&CK framework - able to map common alert types to relevant tactics and techniques and apply that context to triage decisions + Participating in shift handoffs, flagging emerging patterns to Analyst IIs, and raising questions that improve the team's collective awareness * By 180 days: + Carry a full monitoring workload independently across assigned shifts with sound, consistent triage judgment - escalations are timely, severity calls are accurate, and false positive handling is efficient + Partner actively with SOC Analyst IIs on SIEM correlation rule development - contributing observations from day-to-day monitoring that inform rule refinement and detection improvement + Draft or meaningfully improve at least one SOC procedure document, runbook, or triage playbook that gets adopted by the team + Demonstrate working proficiency with at least one SIEM platform beyond basic alert consumption Company Values We have created a fantastic corporate culture - our values drive our behaviors. Here are the expectations: * Passion for cybersecurity and a commitment to maintaining the highest standards of security. * Customer Outcomes: Their success is our success, we are business partners * Entrepreneurial Approach: fast decision making, empowerment, focus on results, test and learn * Win Together: Intense Collaboration, no silos * Integrity is paramount ## Related Videos - [WeAreDevelopers LIVE - Back to CODE100](https://www.wearedevelopers.com/videos/1909-wearedevelopers-live-back-to-code100) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)