24/7 SOC, including nights, weekends, and holidays (40-hour work week, on-call as needed/ emergencies) Hard requirement: CompTIA Security+ certification Position Summary The Security Analyst I handles initial monitoring, detection, triage, and escalation of security events in a 24/7 Security Operations Center (SOC). This role is the frontline of cyber defense, using SIEM and SOAR platforms to identify potential threats, investigate alerts, and escalate on time according to established incident response procedures. It suits a motivated, curious, analytically driven person who thinks critically, adapts quickly, and works well in a fast-paced environment. Key Responsibilities Monitoring & Alert Triage Monitor security events and alerts from SIEM platforms (e.g., Splunk) and other security tools Perform initial triage and investigation to determine severity, scope, and potential impact Analyze logs, network activity, endpoint data, and email security alerts (e.g., Proofpoint) Enrich alerts with context such as threat intelligence, asset data, and user behavior Incident Handling & Escalation Follow defined escalation paths to Tier 2/3 analysts based on severity, confidence, and impact Document incidents, findings, and actions taken in case management systems Execute basic response actions using SOAR platforms (e.g., Splunk SOAR) Assist with containment actions under guidance SOC Operations Support 24/7 SOC operations, including shift work Participate in shift handoffs Maintain situational awareness of threats Platform & Tool Usage Use Splunk SIEM and Splunk SOAR for automation Investigate email threats using Proofpoint Work with Microsoft and Azure security tools Continuous Improvement Improve alert fidelity and reduce false positives Provide feedback for detection tuning Stay current on emerging threats Required Qualifications CompTIA Security+ certification Associate degree in Cybersecurity, IT, or a related field, OR equivalent SOC experience 2+ years in a 24/7 SOC environment Experience with Splunk, Splunk SOAR, and Proofpoint Experience triaging alerts and following escalation processes Knowledge of networking fundamentals and log analysis Familiarity with Microsoft and Azure platforms Preferred Certifications CompTIA CySA+ Splunk Core Certified User Microsoft Security certifications (e.g., SC-200, AZ-500) Core Competencies Analytical thinking, attention to detail, strong communication, adaptability, curiosity and initiative, team collaboration Working Conditions 24/7 SOC environment, including nights, weekends, and holidays On-call or extended hours during incidents Success Metrics Mean Time to Triage (MTTT) Escalation accuracy False positive reduction Documentation quality SLA adherence