WINTrio LLC logo
WINTrio LLC
Posted 71 days agoVerified live 2d ago

SOC Tier I Analyst, 24x7 Monitoring Company Overview

Brief overview

Remote
UndergradOr in progress
2+ yrsMinimum
Microsoft SentinelMicrosoft DefenderKQLSIEM operationsEndpoint securityPhishing alertsIdentity eventsJiraSharePointMicrosoft TeamsSecurity+CySA+CEH

About the company

WINTrio LLC logo
WINTrio LLCwintrio.com

Established in 2014, WINTrio LLC is an SBA 8(a)-certified, HUBZone, and ISO 9001/27001/20000-certified federal IT consulting firm.

Job description

Summary

WINTrio LLC is a leading provider of Cyber/DevSecOps, Cloud, Artificial Intelligence, and Agile Software Development solutions. As a SOC Tier I Analyst, you will support 24x7 monitoring of a federal client’s Microsoft-centric security environment, performing alert triage, validating security events, and documenting findings.

Responsibilities

  • Monitor Microsoft Sentinel and Defender XDR alerts in a 24x7x365 shift environment
  • Perform initial triage of security alerts and determine escalation paths
  • Review identity, endpoint, cloud, network, email, GitHub, SQL, and backup-related alerts
  • Document alert disposition, evidence, false positive rationale, and escalation notes
  • Follow approved playbooks and standard operating procedures
  • Escalate high-severity or suspicious activity to Tier II or Tier III analysts
  • Support monitoring of failed log ingestion, log forwarding issues, and Sentinel pipeline health
  • Assist in daily and weekly security operations reporting
  • Maintain accurate case documentation in SharePoint, Jira, Teams, or other government-furnished tools

Skills

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent experience
  • 2+ years of SOC, help desk security, cybersecurity monitoring, or IT operations experience
  • Basic understanding of SIEM operations, endpoint security, phishing alerts, identity events, and incident escalation
  • Familiarity with Microsoft Sentinel, Microsoft Defender, KQL, or comparable SIEM tools
  • Ability to work assigned shifts, including nights, weekends, or holidays as required
  • Strong documentation and communication skills
  • Microsoft Sentinel, Defender XDR, MDE, MDI, Entra ID
  • KQL basics, Jira, SharePoint, Microsoft Teams
  • Security+, CySA+, SC-200, CEH, or equivalent preferred
  • Experience supporting federal or regulated environments preferred

Qualifications

Must Haves

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent experience
  • 2+ years of SOC, help desk security, cybersecurity monitoring, or IT operations experience
  • Basic understanding of SIEM operations, endpoint security, phishing alerts, identity events, and incident escalation
  • Familiarity with Microsoft Sentinel, Microsoft Defender, KQL, or comparable SIEM tools
  • Ability to work assigned shifts, including nights, weekends, or holidays as required
  • Strong documentation and communication skills

Nice to Haves

  • Microsoft Sentinel, Defender XDR, MDE, MDI, Entra ID
  • KQL basics, Jira, SharePoint, Microsoft Teams
  • Security+, CySA+, SC-200, CEH, or equivalent preferred
  • Experience supporting federal or regulated environments preferred

Benefits

  • Medical, Dental, and Vision Insurance
  • FSA & HSA options
  • 401(k) Retirement Plan
  • Annual Bonus & Profit Sharing
  • Paid Time Off (PTO) & Vacation
  • Employee Assistance Program (EAP)
  • Life & Disability Insurance

More jobs like this