
location_onOn-site
The Information Security Analyst Tier 1 serves as the essential first line of defense within our Security Operations Center (SOC). This position is designed for professionals who wish to transition from traditional monitoring into the dynamic fields of Detection Engineering and Security Orchestration (SOAR). You will go beyond simple alert triage to own the end-to-end investigation and documentation of security incidents, analyzing threats ranging from phishing to sophisticated compromised account scenarios.
Your daily workflow involves leveraging SIEM, EDR platforms, and email security gateways to identify and mitigate risks. A critical component of this role is driving operational excellence; you will actively contribute to the SOC's evolution by refining detection logic, automating manual tasks, and maintaining comprehensive security playbooks. Additionally, you will manage user access requests to security tools, ensuring secure identity management while maintaining detailed logs for compliance and seamless hand-offs.
This role operates during standard business hours with no on-call rotation, offering a stable environment to develop deep technical expertise in a proactive defense model.
Work model: On-site
On-site
Skills: Siem, Edr, Soar, Python, Powershell, Splunk, Phishing Analysis, Header Analysis, Attachment Detonation, Identity And Access Management.
Education: Bachelor's Degree or equivalent combination of education and experience; Bachelor's Degree or higher in Cybersecurity, Computer Science, or related technical discipline.
Bachelor's Degree or higher in Cybersecurity, Computer Science, or a related technical discipline. 3+ years experience in an enterprise Security Operations Center or IT environment. Experience investigating compromised accounts, including analyzing authentication logs, sessions, and MFA events. Experience building or tuning detections within a SIEM (Splunk preferred) or EDR tool. Basic to Intermediate experience with Automation using Python, PowerShell, or SOAR tools. Experience with Email Security Gateways and performing deep-dive phishing analysis. Experience managing User Access Requests and Identity and Access Management (IAM) principles. Experience writing hand-off notes, incident reports, and SOPs. Experience working with Cloud technologies. Knowledge of Detection Engineering principles (e.g., mapping to MITRE ATT&CK). Familiarity with API-based integrations for security automation. Understanding of network protocols (TCP/IP, DNS, HTTP) and cloud security fundamentals. Understanding of HTTP/HTTPS protocols and response codes. Familiarity with security frameworks (NIST, CIS) and risk/compliance initiatives.