Post a job

Security Operations Center (SOC) Analyst - Remote

OSIbeyond · United States · posted today ago

Apply for this role

engineeringsecurityoperationsremote jobs in united states
Listing supplied by Himalayas. 101 Careers did not originate this post and applications are handled by the employer.

About this role

Since 2004, OSIbeyond has delivered managed technology and cybersecurity services on a founding principle: outstanding technical expertise, matched by an exceptional customer experience. Today, that commitment is delivered through OSIbeyond ONE, our integrated technology platform that unifies IT operations, cybersecurity, Microsoft 365, cloud, automation, AI, and expert support into a single, continuously managed environment. The platform is built on a clear operating philosophy: Automation First. AI Enabled. People Powered.

The OSIbeyond Security Operations Center is the cybersecurity engine of that platform. It provides continuous detection, investigation, and response across a diverse portfolio of client environments, including organizations subject to federal compliance frameworks such as CMMC and NIST SP 800-171. The SOC operates on a two-shift, automation-augmented coverage model. Human analysts staff the Day and Evening shifts, and a purpose-built automation layer operates overnight, backed by an on-call analyst, ensuring that every hour of every day is covered by a trained analyst or by an automated response workflow.

The SOC Analyst is the “People Powered” element of security operations. Automation handles the repetitive, high-volume work of enrichment, correlation, and first-response containment, so that the analyst’s time is concentrated on the work that requires human judgment: validating and investigating alerts, leading incident response, advising clients, and continuously improving detection and automation logic. The SOC engineering team is continuously expanding this automation capability, and analysts are expected to contribute to that evolution as active participants rather than passive users.

This position is suited to a technically accomplished security professional who values structure, precision, and accountability. The successful candidate demonstrates sound analytical judgment, disciplined documentation, professionalism in client communication, and a commitment to protecting client environments with the same care they would expect for their own.

ABOUT THE ROLE:

The SOC Analyst monitors, analyzes, and responds to cybersecurity threats across client environments. The analyst operates the SOC’s security tooling, investigates suspicious activity, contains and remediates confirmed incidents, and communicates findings clearly to clients and internal stakeholders.

During each shift the analyst owns the live alert queue, triaging detections from the SIEM, endpoint, identity, and email security platforms; determining scope and severity; and executing or authorizing the appropriate response. Because the SOC operates on a shift model, the analyst is also responsible for the integrity of coverage: conducting structured handoffs at the end of each shift, reviewing existing alerts at the start of the Day shift, and ensuring that no detection, investigation, or client commitment is left without a clear owner.

Beyond day-to-day operations, the analyst performs scheduled vulnerability scanning, conducts root cause analysis for security incidents, and identifies repetitive manual work that should be transitioned to automation. Performance is measured against response times, investigation quality, SLA adherence, documentation standards, and contributions to the continuous improvement of detection and automation.

SCHEDULE & SHIFT MODEL:

The SOC operates a two-shift model with 12-hour shifts. Each analyst is assigned to a fixed shift (Day or Evening) and does not rotate between shift times. The two shifts overlap for six hours (11:00 AM to 5:00 PM), providing a structured handoff window and dual-analyst coverage during peak business hours. Overnight coverage (11:00 PM to 5:00 AM) is provided by the SOC’s Tines automation layer, which performs enrichment, containment, and escalation according to documented playbooks. Escalations that exceed the automation’s authority are routed to the on-call SOC Analyst.

ESSENTIAL DUTIES & RESPONSIBILITIES:

Security Monitoring & Alert Triage (≈50%)

Incident Investigation & Response (≈25%)

Vulnerability Management & Security Posture (≈10%)

Automation Oversight & Continuous Improvement (≈15%)

General Responsibilities

SUCCESS METRICS:

SECURITY RESPONSIBILITIES:

QUALIFICATIONS:

Experience

Security Operations Skills

Systems & Network Knowledge

Automation & Operational Skills

Additional Desirable Qualifications

KNOWLEDGE & CERTIFICATIONS

Tooling Environment: SIEM and extended detection and response platforms; Sentinel One and Blumira; Entra ID identity protection; Tines security automation; vulnerability scanning platform; Autotask professional services automation (ticketing); Microsoft Teams for internal collaboration.

Required Certifications (or attainment within the first six months)

CompTIA Security+

CompTIA Network+

Preferred Certifications

CompTIA SecurityX (CASP+) or other DoD 8140 Level II certification

Position:

Benefits:

Salary: Based on Experience

Originally posted on Himalayas

Similar remote engineering jobs

Browse all remote engineering jobs →

Security Operations Center (SOC) Analyst - Remote at OSIbeyond — Remote | 101 Careers