Job Closed
This listing is no longer active.
Night Shift SOC Analyst - Level 1
Location
United States
Posted
28 days ago
Salary
0
Seniority
Mid Level
Job Description
Night Shift SOC Analyst - Level 1
Coretek Services
Role Description Join a highly skilled and motivated team of Cyber Security Professionals tasked with protecting Coretek and its customers. The Cyber Security Analyst Level 1 (SOC Analyst L1) is an entry-level role responsible for the initial detection, triage, and response to security alerts. This includes: - Monitoring security tools - Performing basic analysis to identify false positives - Following predefined playbooks for initial response - Escalating complex or high-priority incidents to Level 2 analysts with detailed documentation Analysts will leverage SIEM/SOAR platforms, cyber case management, and supplementary tools to investigate, contain, and remediate cyber security incidents. The role requires a drive to learn and grow as the industry and Coretek evolve rapidly. Coretek recognizes candidates may lack some skills for this unique service provider role and will train and develop the right fit. Desire to learn and collaborate within a team is essential. Skills from other disciplines demonstrate adaptability and are welcome. Formal education or self-taught backgrounds are valued. Structured training and on-the-job experience will prepare analysts for the complex requirements and fast-paced environment of a service provider. Analysts must adapt to industry changes. Qualifications - Familiarity with SIEM (e.g., Elastic, Splunk, QRadar), firewalls, IDS/IPS, and endpoint tools - Basic knowledge of networking like TCP/IP, DNS, VPN, and protocols (HTTP, FTP) - Awareness of common threats (phishing, malware, DDoS) and attack vectors - Ability to triage alerts, separating false positives from real threats - Skill in following playbooks and SOPs for initial response and remediation - Strong attention to detail for monitoring events and spotting anomalies - Clear documentation of incidents, timestamped for audits or escalations - Effective communication to report findings and escalate to Level 2 - Team collaboration, especially in incident scenarios - Handle multiple tasks in a high-pressure, dynamic environment - Willingness for 24/7 shifts, including nights and weekends - Sense of urgency and duty in incident response - Composure under pressure during active incidents Requirements - Monitor alerts from SIEM, firewalls, IDS/IPS, and other systems to spot incidents - Triage alerts by severity, impact, and urgency using set criteria - Collect initial alert details like source, target, timestamp, and logs - Use playbooks and SOPs for preliminary analysis to check for false positives or escalation needs - Perform containment actions per playbooks, such as blocking IPs or isolating systems - Verify remediation effectiveness and document actions with timestamps - Collaborate with teams to solve blockers innovatively - Escalate advanced incidents based on severity, impact, or complexity thresholds - Provide detailed logs, analysis, and context for smooth handoff to Level 2 - Notify Level 2 or response teams quickly, noting urgency and risks - Document incidents accurately per SOC standards, including alerts and outcomes - Keep records organized, timestamped, and accessible for audits - Update supervisors and Level 2 on status, key findings, and actions needed Benefits - Structured training and on-the-job experience Shift Specifics - 7 a.m. - 7 p.m. Mon-Tues-Wed - 7 a.m. - 7 p.m. Sun-Mon-Tues every third or 4th week Education and Training - Degree in cybersecurity, IT, related field preferred, or equivalent experience - Entry-level certs like CompTIA Security+, Cisco CCNA, or equivalent experience - Security certifications desired
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
IT Cybersecurity Analyst
GuidehouseGuidehouse, a "next-generation consultancy" and a portfolio company of Veritas Capital, provides management, risk consulting, and technology services to help cl
• Provide support for risk assessments and risk analysis tasks • Assist with control reviews and compliance activities • Gather and organize audit evidence and documentation • Coordinate escalations and support requests during U.S. business hours • Help maintain consistent and scalable GRC workflows as programs grow.
• Monitor open-source, dark web, and underground forums for threats relevant to Moniepoint and the financial sector • Track ransomware groups, stealer malware, phishing campaigns, brand impersonation, and fraud-related threats • Collect Indicators of Compromise (IOCs) including domains, IPs, URLs, hashes, and malicious infrastructure • Perform basic triage and analysis of threat data to determine relevance and risk • Assist in identifying adversary tactics, techniques, and procedures (TTPs) • Support mapping of threats to MITRE ATT&CK where applicable • Contribute to daily, weekly, and ad-hoc threat intelligence reports • Share relevant intelligence with relevant stakeholders • Assist in validating alerts and external threat reports • Support investigations related to phishing, account takeover, and third-party risks • Maintain threat logs, actor profiles, and intelligence repositories • Document analytical findings clearly and concisely • Learn and apply CTI frameworks, tools, and best practices • Assist in Incident Response tasks and post-incident analysis when needed. • Conduct regular vulnerability scans and assessments on networks, systems, and applications. • Analyze scan results to identify vulnerabilities, potential risks and ensure timely remediation.
Cyber Security Analyst
Finance of AmericaEmpowering 55+ customers with modern reverse mortgage options to fund the next chapter in life. NMLS #2285
• Conduct deep investigations into security events • Correlate data across multiple platforms • Lead incident response activities for moderate-complexity threats • Refine detection logic and improve SOC workflows • Provide guidance to Level I analysts • Utilize Crowdstrike, Azure/M365, Elastic/Kibana for event correlation • Lead investigations for escalated alerts • Perform containment actions following established procedures • Review and tune detections and alerts • Participate in threat hunting missions • Document incident timelines and root causes • Maintain awareness of current threats and security policies
Threat Intelligence Analyst
MercorCincinnatus is an enterprise staffing company that partners with leading technology companies to source and employ highly skilled professionals for full-time and long-term contingent roles. Cincinnatus serves as the employer of record for these engagements, providing W-2 employment, payroll, benefits, and compliance, while placing employees directly within client teams to work on high-impact initiatives. Roles hired through Cincinnatus are not project-based or freelance engagements. They are structured, role-based positions that typically involve full-time or fixed-term commitments, close collaboration with a client's internal teams, and integration into standard enterprise workflows. Cincinnatus is a legal entity separate from Mercor. While opportunities may be discovered through Mercor's platform, employment, onboarding, payroll, and benefits for these roles are administered by Cincinnatus. Equal Employment Opportunity Cincinnatus is proud to be an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or any other legally protected characteristic. Cincinnatus is committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans throughout the job application process.
Role Description - Analyze online information environments to identify manipulation patterns using cybersecurity methods. - Apply OSINT workflows to conduct thorough disinformation analysis. - Evaluate ambiguous online data to improve threat intelligence processes. - Collaborate with cybersecurity teams to enhance investigative methods. - Develop strategies for adversarial analysis and influence operations detection. - Work independently and asynchronously to meet project goals. Qualifications - Must-Have: - Experience in cybersecurity research, threat intelligence, or OSINT investigations. - Strong skills in disinformation analysis and adversarial analysis. - Preferred: - Background as a Trust & Safety analyst with technical depth. - Experience as a security engineer with investigation expertise. Requirements - Contract position. - Compensation: $100/hour. - Location: Remote. Company Description Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers, and Jack Dorsey.


