Summary
The company is a communications organization seeking a SOC Analyst Level I to support cybersecurity operations. The role focuses on monitoring security events, triaging and responding to incidents, documenting activity in Splunk and ServiceNow, conducting threat research, and collaborating on remediation and security control improvements.
Responsibilities
- Work in a fast-paced, SLA-driven Security Operations Center (SOC), using tools such as Splunk (SIEM) and ServiceNow to help identify and manage security incidents
- This position is ideal for individuals looking to build a strong foundation in cybersecurity operations within a structured and process-driven environment, with opportunities for growth and skill development
- Monitor security events and alerts using Splunk SIEM to identify suspicious activity across network, endpoint, and cloud environments
- Perform initial triage and investigation of alerts, following defined procedures to determine severity and required actions
- Respond to security incidents in accordance with established SLAs, ensuring timely escalation and proper handling
- Use ServiceNow to log, track, and document incidents, maintaining accurate records throughout the lifecycle
- Conduct basic threat research to stay informed on emerging threats, vulnerabilities, and attacker techniques
- Support incident analysis by identifying contributing factors and assisting with remediation recommendations
- Collaborate with security engineering, and threat hunting to resolve incidents and strengthen security controls
- Follow and contribute to standard operating procedures (SOPs) and playbooks to ensure consistent incident response
- Communicate clearly with internal stakeholders regarding incident status and actions taken
- Support day-to-day operational activities within the team
- Perform technical and operational tasks aligned with business needs
- Work may involve hands-on operational support, troubleshooting, and maintenance-type responsibilities (inferred based on role title)
Skills
- Bachelor's degree in Cybersecurity, Information Technology, or a related field (or equivalent experience)
- Proficient understanding of SOC operations and the incident response lifecycle
- Familiarity with SIEM tool Splunk
- Exposure to ServiceNow or similar ticketing systems
- Knowledge of networking fundamentals, security principles, and log analysis
- Strong analytical and problem-solving skills
- Effective written and verbal communication skills
- Familiarity with threat intelligence concepts or frameworks such as MITRE ATT&CK
- 2+ years of hands-on experience in security monitoring or incident response environments
- Candidates should be able to operate independently and contribute to ongoing operations
- Hands-on experience with Splunk SIEM is mandatory; ~90% of the work will be performed within Splunk
- Candidates should have practical experience and/or Splunk certification
- Relevant certifications (e.g., CompTIA Security+, Splunk certifications)
Qualifications
Must Haves
- Bachelor's degree in Cybersecurity, Information Technology, or a related field (or equivalent experience)
- Proficient understanding of SOC operations and the incident response lifecycle
- Familiarity with SIEM tool Splunk
- Exposure to ServiceNow or similar ticketing systems
- Knowledge of networking fundamentals, security principles, and log analysis
- Strong analytical and problem-solving skills
- Effective written and verbal communication skills
- Familiarity with threat intelligence concepts or frameworks such as MITRE ATT&CK
- 2+ years of hands-on experience in security monitoring or incident response environments
- Candidates should be able to operate independently and contribute to ongoing operations
- Hands-on experience with Splunk SIEM is mandatory; ~90% of the work will be performed within Splunk
- Candidates should have practical experience and/or Splunk certification
Nice to Haves
- Relevant certifications (e.g., CompTIA Security+, Splunk certifications)
Benefits
- Health Benefits
- Referral Program
- Excellent growth and advancement opportunities
- Work model: remote