SOC Analyst

Horizon3.ai
United States
Workplace: RemoteFull timeUSD 123,850 - 161,000 annuallyFunction: CybersecurityExperience: 3-6 yearsEducation: bachelorsSkills: ["Analytical thinking","Problem-solving","Communication","Documentation","Ownership"]

Monitor and triage security events in a high-scale, cloud-native SOC, owning SIEM health and threat detection workflows. Support log ingestion and analytics across AWS, Okta, endpoints, firewalls, and SaaS, and build SIEM dashboards and KPIs. Tune detection rules to reduce false positives, validate alerts with MITRE ATT&CK context, and escalate confirmed incidents. Improve response playbooks and contribute to SOAR automation and LLM-assisted investigations with verification.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Horizon3.ai
Horizon3.ai
2 days ago

SOC Analyst

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 13 hours agoStatus: Live

Job Summary

Monitor and triage security events in a high-scale, cloud-native SOC, owning SIEM health and threat detection workflows. Support log ingestion and analytics across AWS, Okta, endpoints, firewalls, and SaaS, and build SIEM dashboards and KPIs. Tune detection rules to reduce false positives, validate alerts with MITRE ATT&CK context, and escalate confirmed incidents. Improve response playbooks and contribute to SOAR automation and LLM-assisted investigations with verification.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Monitor, detect, and respond to security events across enterprise environments using the SIEM.
  • •Support log ingestion, parsing, and normalization and monitor ingestion health across AWS, Okta, endpoints, firewalls, and SaaS sources.
  • •Build and maintain dashboards, visualizations, and KPIs to demonstrate SIEM effectiveness and security visibility.
  • •Triage, investigate, and validate alerts, escalating confirmed or ambiguous incidents with clear context.
  • •Tune and test detection rules and use MITRE ATT&CK to contextualize detections and identify coverage gaps, following and refining incident response playbooks.
Travel: Low travel

Pay and Benefits

Salary: USD 123,850 - 161,000 annually
Equity and Bonus:Equity
Perks:Health InsuranceVisionDentalParental LeaveEquity

Key Requirements

  • •3–6 years in a SOC or security analyst role with hands-on SIEM monitoring, alert triage, detection tuning, and incident response.
  • •Working experience with an enterprise SIEM such as Elastic SIEM (preferred), Splunk, Microsoft Sentinel, QRadar, or similar.
  • •Strong log analysis, security telemetry, and event correlation skills.
  • •Proficiency with detection-rule authoring and query languages (KQL, Lucene, SPL) and scripting in Python, Bash, or PowerShell.
  • •Familiarity with MITRE ATT&CK, NIST, and CIS, plus at least one major cloud (AWS, GCP, or Azure) and its security tooling.
Experience:3-6 yearsCybersecuritySOC
Education:Bachelor's in Computer Science, Cybersecurity, Information Security, or a related field
Skills:Analytical thinkingProblem-solvingCommunicationDocumentationOwnership
Certifications:Security+CySA+GCIAGCIHElastic Certified Analyst
Tech Stack:Elastic SIEMSplunkMicrosoft SentinelQRadarKQLLuceneSPLPythonBashPowerShellAWSGCPAzureMITRE ATT&CKNISTCISSOARTinesLLMAI

Eligibility

Security Clearance:US Federal

Company Brief

Horizon3.ai
Builds NodeZero®, an autonomous penetration-testing platform that continuously finds, prioritizes, and verifies exploitable vulnerabilities across on-premises, cloud, and hybrid environments to help organizations reduce security risk.
Industry: Cybersecurity
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Funding: Series D
Headquarters: San Francisco, United States
Founded: 2019
Glassdoor
Glassdoor: 4.9
WebsiteLinkedInGlassdoor