What are the responsibilities and job description for the SOC Analyst position at Strategy Resources, LLC?
Position Overview
We are seeking a motivated Junior SOC Analyst with 1 to 3 years of hands-on experience to join our Security Operations Center (SOC) team. In this role, you will provide frontline operational support under Cybersecurity Operations and Operational Support (SecOps). You will be responsible for real-time monitoring, triage, initial incident response, vulnerability coordination, and baseline security tooling maintenance to ensure continuous visibility and defense across enterprise environments.
Key Responsibilities
1. Security Monitoring & Triage (Tier 1 SecOps)
● Monitor real-time alert queues from SIEM (e.g., Splunk, Microsoft Sentinel, Elastic) and EDR platforms to detect suspicious activity, policy violations, and unauthorized access attempts.
● Perform initial triage, log parsing, and correlation across network, host, identity, and cloud telemetry (Windows Event Logs, Syslog, firewall/proxy logs).
● Distinguish false positives from actionable security events; document analysis steps and escalate verified threats to Tier 2/Tier 3 Incident Responders following established Standard Operating Procedures (SOPs).
2. Incident Handling & Operational Escalation
● Assist in the containment and remediation of low-to-medium severity security incidents (e.g., phishing, commodity malware, credential stuffing) using pre-approved playbooks.
● Coordinate with IT operations, service desks, and system administrators during containment actions (e.g., isolating endpoints, resetting compromised credentials, blocking malicious IPs/domains).
● Maintain clear, auditable incident tickets and shift handover logs within the enterprise ticketing system (e.g., ServiceNow, Jira).
3. SecOps Tooling & Health Maintenance
● Assist in health checks and operational verification of security infrastructure, agents, and sensors across endpoints and network segments.
● Validate log ingestion status and report visibility blind spots, agent communication failures, or corrupted telemetry streams to senior SecOps engineers.
● Assist with the review and basic tuning of alerting rules to reduce operational alert fatigue.
4. Vulnerability & Threat Operational Support
● Review vulnerability scan outputs and correlate identified weaknesses with active threats and asset inventories.
● Track patching and remediation status in partnership with systems and network administration teams.
● Ingest and operationalize tactical Cyber Threat Intelligence (CTI), applying known Indicators of Compromise (IOCs) to active monitoring searches.
Qualifications & Requirements
Education & Experience
● Experience: 1–3 years of professional experience in an active SOC environment, incident triage, or a blended IT helpdesk/security operations role.
● Education: Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or equivalent practical experience / military service.
Technical Skills
● SIEM / Log Analysis: Hands-on experience navigating SIEM platforms (Splunk, Sentinel, QRadar, or equivalent) and writing basic search queries/filters (e.g., KQL, SPL).
● Endpoint & Network Detection: Working knowledge of modern EDR/XDR tooling (CrowdStrike, Defender for Endpoint, Carbon Black) and network security telemetry (firewall, proxy, DNS, IDS/IPS).
● Operating Systems & Networking: Solid understanding of Windows and Linux OS internals, TCP/IP fundamentals, common application protocols (HTTP/S, DNS, SMB, SSH, RDP), and enterprise Active Directory/Azure AD architecture.
● Threat Frameworks: Basic familiarity with the MITRE ATT&CK® framework and the Cyber Kill Chain.
Certifications (Preferred / Desirable)
● CompTIA Security , CySA , or Network
● GIAC Foundational/Operations Certifications (GSEC, GCIH)
● Vendor-specific practitioner accreditations (e.g., Microsoft SC-200, Splunk Core Certified Power User)
Soft Skills
● Strong analytical and pattern-recognition abilities under operational pressure.
● Clear written and verbal communication skills for cross-team coordination and executive-level incident notes.
● Eagerness to continuously learn, adapt to evolving threat surfaces, and participate in rotational shift schedules if required.
Salary : $65,000 - $75,000