SOC Analyst
Clear CapitalRemote (USA)Full-Time3w ago
Job description
SOC Analyst at Clear Capital.
About the role
In this position, you will play a crucial role in protecting our digital assets, both on-site and in cloud environments. Your primary responsibilities will include monitoring for potential threats, responding to security incidents, and actively searching for vulnerabilities within our systems. This role is essential for maintaining the integrity and security of our information technology infrastructure.
Key facts
What you'll do
- Continuously monitor and analyze security alerts generated from various sources such as SIEM, EDR/XDR, IDS/IPS, firewalls, cloud services, identity management systems, and endpoint security applications.
- Engage in incident response activities, which involve assessing alerts, conducting root cause analyses, proposing containment measures, and documenting all findings for future reference.
- Investigate activities across multiple systems, including endpoints, authentication logs, firewalls, VPNs, cloud infrastructures, and networks, to identify indicators of compromise, unauthorized access, and other suspicious activities.
- Provide expert advice on vulnerability management by reviewing security findings, evaluating technical risks, and guiding system owners on remediation efforts and their potential business impacts.
- Share practical recommendations for enhancing security through system hardening, secure configurations, and control improvements, while adhering to established industry standards like CIS Benchmarks.
- Collaborate on infrastructure projects and initiatives, ensuring that security best practices are integrated and that compliance with company policies is maintained.
- Develop and maintain documentation related to security processes, incident response procedures, and threat hunting methodologies.
- Participate in ongoing training and professional development to stay current with the latest security trends and technologies.
Requirements
- A Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related discipline, or equivalent professional experience is required.
- At least 5 years of experience in security roles, particularly within a Security Operations Center (SOC), focusing on threat detection, incident response, and security event analysis.
- Demonstrated experience in investigating actual security incidents using data from SIEM, EDR/XDR, firewalls, identity systems, endpoints, cloud environments, or network telemetry.
- Strong understanding of incident response frameworks, threat hunting techniques, attacker methodologies, log analysis, event correlation, detection tuning, and security investigation processes.
- Experience in reviewing vulnerability assessments, evaluating technical risks, prioritizing remediation actions, and advising stakeholders based on findings from vulnerability management tools.
- Familiarity with operating systems such as Windows, macOS, and Linux, as well as knowledge of Active Directory, cloud environments, networking principles, endpoint security, and security frameworks like CIS Benchmarks, NIST, CIS Controls, RMF, and MITRE ATT&CK.
- A relevant technical security certification is mandatory.
Nice to have
- Preferred certifications include CompTIA CySA+, CompTIA CASP+, GIAC GCIH, GIAC GCIA, GIAC GSOC, GIAC GMON, or other equivalent hands-on certifications related to SOC operations, incident response, threat hunting, or blue-team activities.
- Experience with cloud security platforms and identity and access management tools.
- Familiarity with vulnerability management platforms and their integration into security workflows.
Skills & tools
- Proficient in using SIEM tools
- Experience with EDR/XDR solutions
- Knowledge of IDS/IPS systems
- Familiarity with firewalls and their configurations
- Understanding of cloud security platforms
- Proficient in identity and access management tools
- Experience with endpoint security solutions
- Familiarity with vulnerability management platforms
- Knowledge of Windows, macOS, and Linux operating systems
- Proficient in Active Directory management
- Understanding of networking protocols
- Familiarity with the MITRE ATT&CK framework
- Knowledge of CIS Benchmarks and NIST frameworks
Practical notes
-
Compensation: The annual salary for this position ranges from $113,800 to $139,000, depending on your location, experience, and qualifications. Additional compensation may include a profit-sharing bonus program, communication stipends, and referral bonuses.
- Benefits: A comprehensive benefits package is offered, including medical, dental, and vision insurance, a 401(k) plan with employer matching, voluntary life and AD&D insurance, supplemental insurance options, paid time off, paid holidays, employee assistance programs, wellness initiatives, company-paid short-term disability, and contributions to health savings accounts. Employees will also have access to virtual primary care through Galileo and mental health resources via Rula.
- Visa sponsorship: Not mentioned.