It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies. All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.
Security Operations Center (SOC) Analyst I
Location
United States
Posted
5 days ago
Salary
0
Seniority
Mid Level
No structured requirement data.
Job Description
Security Operations Center (SOC) Analyst I
ASM Research
Role Description The Security Operations Center (SOC) Analyst I is a frontline cyber defender responsible for monitoring security tools and dashboards to identify indicators of compromise across networks, endpoints, and cloud‑hosted systems in mission‑critical environments. The role focuses on triaging and analyzing alerts from SIEM and other monitoring platforms, distinguishing true incidents from benign activity and escalating confirmed threats to senior analysts or incident responders. SOC Analyst I staff support basic threat detection, documentation of security events, and coordination with IT and security teams for initial containment, while contributing to tuning rules, improving playbooks, and maintaining awareness of common attack techniques and vulnerabilities. - Monitor SIEM platforms and log analysis tools to triage security alerts across network, system, and application layers, identifying potential indicators of compromise. - Investigate suspicious activity using data from firewalls, IDS/IPS, endpoint protection, and cloud security services to identify potential threats and determine whether escalation is warranted. - Apply standard incident response playbooks and procedures, including initial containment steps, evidence preservation, and effective handoff to Tier II or incident response teams. - Review vulnerability scanning outputs and apply basic risk prioritization concepts to recognize misconfigurations and exploitable weaknesses in enterprise environments. - Document security events and incidents with accurate case records and concise reports that support post‑incident review and continuous improvement activities. - Follow security frameworks and best practices relevant to highly regulated government or enterprise environments, including access control, monitoring, and logging requirements for mission‑critical systems. - Participate in rule tuning and playbook improvements, providing feedback on false positives, emerging patterns, and common attack vectors, malware behaviors, and phishing techniques. Qualifications - Bachelor’s Degree in Computer Science, Information Assurance, Cybersecurity, or a related field, or equivalent relevant experience (aligned to Operations Security Planner I standard). - Typically 1–3 years of hands‑on experience in IT support, networking, or cybersecurity operations roles, including exposure to security monitoring or incident response. - Proficiency with SIEM platforms and log analysis tools for monitoring and triaging security alerts across multiple layers (network, system, application). - Ability to investigate suspicious activity using data from firewalls, IDS/IPS, endpoint protection, and cloud security services, with foundational knowledge of common attack vectors and malware behaviors. - Familiarity with basic incident response processes, including initial containment, evidence preservation, and structured escalation to Tier II or incident response teams. - U.S. Citizenship required, with ability to satisfy background investigation requirements appropriate to a federal IT environment. - Strong written and verbal communication skills, with attention to detail in documenting incidents and maintaining accurate case records. Preferred Qualifications - Experience with at least one enterprise SIEM (e.g., Splunk, QRadar, Azure Sentinel) and creation or tuning of correlation rules. - Foundational cybersecurity certification such as CompTIA Security+, CySA+, or equivalent vendor‑neutral credential. - Exposure to 24x7 operations or shift‑based monitoring environments supporting large, complex networks. - Familiarity with vulnerability scanning tools and outputs, and with standard security frameworks used in highly regulated government or enterprise environments. Compensation Ranges Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees. EEO Requirements It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies. All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment. Physical Requirements The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions. Disclaimer The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
Security Operations Center (SOC) Analyst II
ASM ResearchIt is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies. All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.
Role Description The Security Operations Center (SOC) Analyst II serves as a mid‑level cyber defender responsible for continuous monitoring, investigation, and response to security events across enterprise networks, endpoints, and cloud environments in a highly regulated government setting. This Tier 2 role handles alerts escalated from Tier 1, performing deeper analysis, driving containment and mitigation recommendations, and supporting coordinated remediation for mission‑critical systems. The analyst helps operate and tune SOC technologies such as SIEM, EDR/XDR, IDS/IPS, and threat intelligence platforms while improving playbooks, use cases, and procedures to enhance detection fidelity and reduce false positives. - Conduct in‑depth analysis of security alerts escalated from Tier 1, correlating logs, network traffic, endpoint telemetry, and threat intelligence to determine incident scope, impact, and root cause. - Operate and tune SIEM, EDR/XDR, IDS/IPS, and related SOC tooling to improve detection fidelity, reduce false positives, and enhance visibility across on‑premises and cloud environments. - Execute Tier 2 incident response activities, including containment and mitigation recommendations, coordination with infrastructure and application teams, and support for digital evidence collection and documentation. - Review and apply emerging cyber threat intelligence, including indicators of compromise and adversary TTPs, to update rules, playbooks, and monitoring use cases aligned to frameworks such as MITRE ATT&CK. - Maintain accurate and detailed case records in ticketing and case‑management systems, supporting 24x7 operations with clear handoffs, status reporting, and after‑action inputs. - Support compliance‑driven operations in a highly regulated government environment by following established SOPs, incident handling processes, and security control requirements for mission‑critical systems. - Collaborate with and mentor Tier 1 analysts by providing guidance on triage techniques, escalation criteria, and best practices for investigating suspicious activity. Qualifications - Bachelor’s Degree in Computer Science, Information Assurance, Cybersecurity, or a closely related field, or equivalent relevant experience. - Typically 3–5 years of prior experience in a SOC, cyber incident response, or closely related security operations role handling Tier 1/Tier 2 investigations. - Demonstrated hands‑on experience operating and tuning SIEM, endpoint security (EDR/XDR), IDS/IPS, and related SOC tools in enterprise environments. - Strong analytical skills in log analysis, network traffic review, and endpoint telemetry, with the ability to determine incident scope, impact, and probable root cause. - Familiarity with cyber threat intelligence concepts, indicators of compromise, and adversary TTPs, and experience applying these within monitoring and detection use cases. - U.S. Citizenship required, with ability to satisfy background investigation requirements appropriate to a federal IT environment. - Ability to work effectively as part of a 24x7 SOC operation, including clear written and verbal communication for case documentation and handoffs. Preferred Qualifications - Experience with leading SIEM and endpoint security platforms such as Splunk, Microsoft Sentinel, Microsoft Defender, or similar tools. - Industry certifications such as Security+, CySA+, GCIH, or equivalent SOC/incident response credentials. - Prior experience supporting federal or other highly regulated environments requiring U.S. citizenship and eligibility for a clearance or public trust. - Familiarity with frameworks such as MITRE ATT&CK and NIST 800‑series as they relate to SOC use cases, detection engineering, and incident handling. Compensation Ranges Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees. EEO Requirements It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies. All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment. Physical Requirements The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions. Disclaimer The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.
Manager, Offensive Product Cybersecurity and Product Security Operations Center
General MotorsJoin us on our journey toward a world with zero crashes, zero emissions, and zero congestion.
Title: Manager, Offensive Product Cybersecurity & PSOC Location: Warren, Milford, Michigan, United States of America Job Description: Full time job requisition id JR-202615164 Job Description The Role The Manager, Offensive Product Cybersecurity & PSOC leads two key areas within GM’s Product Cybersecurity organization: offensive product security services and the Product Security Operations Center (PSOC). This leader oversees penetration testing, red team operations, and security research to strengthen confidence in the security of GM’s products, while also owning product security operations, including security-readiness visibility, detection and response, bug bounty management, and product security incident response (PSIRT). What You'll Do - Lead a team of 10+ product cybersecurity engineers across offensive security and security operations. - Define a comprehensive set of offensive security services and capabilities to ensure a secure product portfolio. - Establish and manage a product security assessment schedule in partnership with product management teams. - Develop and formalize a security research plan focused on forward-looking technology investments. - Own product cybersecurity operations strategy and data sources to enable effective detection and response. - Coordinate with third-party security researchers through the bug bounty program and lead PSIRT activities. Your Skills and Abilities (Required Qualifications) - 8+ years of security experience in product security teams or similar security functions. - 4+ years of leadership experience in penetration testing, security research, product security, or closely related roles. - Expertise in embedded security, including operating system, application, and hardware contexts. - Experience defining a team calendar of work that incorporates stakeholder and business-wide priorities. - Ability to read and write software in multiple languages to support investigation and remediation efforts. - Proven leadership of incident response activities involving time-sensitive and confidential workflows. What Will Give You a Competitive Edge (Preferred Qualifications) - Prior experience in the automotive industry or a similarly complex, deadline-driven, and regulated environment. - Published cybersecurity research (e.g., conference talks, blog posts, or public code repositories). - Experience architecting security operations platforms and leading security analysts in triaging risk-based findings. - Experience building custom security tooling and/or extending functionality in related technologies. - A detailed, high-ownership leadership style that connects vision to clearly articulated strategy. - Ability to manage multiple complex projects simultaneously with defined milestones and success criteria. - Strong commitment to internal customer relationships that drive high-quality security outcomes. - Deep technical expertise that supports confident, opinionated work planning and team mentorship. - Ability to communicate technical content effectively to various levels of leadership and external audiences, including media. Company Vehicle: Upon successful completion of a motor vehicle report review, you will be eligible to participate in a company vehicle evaluation program, through which you will be assigned a General Motors vehicle to drive and evaluate. Note: program participants are required to purchase/lease a qualifying GM vehicle every four years unless one of a limited number of exceptions applies. GM does not provide immigration-related sponsorship for this role. Do not apply for this role if you will need GM immigration sponsorship now or in the future. This includes direct company sponsorship, entry of GM as the immigration employer of record on a government form, and any work authorization requiring a written submission or other immigration support from the company (e.g., H1-B, OPT, STEM OPT, CPT, TN, J-1, etc). This role is categorized as hybrid. This means the selected candidate is expected to report to a specific location at least 3 times a week {or other frequency dictated by their manager}. This job may be eligible for relocation benefits. About GM Our vision is a world with Zero Crashes, Zero Emissions and Zero Congestion and we embrace the responsibility to lead the change that will make our world better, safer and more equitable for all. Why Join Us We believe we all must make a choice every day – individually and collectively – to drive meaningful change through our words, our deeds and our culture. Every day, we want every employee to feel they belong to one General Motors team. Benefits Overview From day one, we're looking out for your well-being–at work and at home–so you can focus on realizing your ambitions. Non-Discrimination and Equal Employment Opportunities (U.S.) General Motors is committed to being a workplace that is not only free of unlawful discrimination, but one that genuinely fosters inclusion and belonging. We strongly believe that providing an inclusive workplace creates an environment in which our employees can thrive and develop better products for our customers. All employment decisions are made on a non-discriminatory basis without regard to sex, race, color, national origin, citizenship status, religion, age, disability, pregnancy or maternity status, sexual orientation, gender identity, status as a veteran or protected veteran, or any other similarly protected status in accordance with federal, state and local laws. We encourage interested candidates to review the key responsibilities and qualifications for each role and apply for any positions that match their skills and capabilities. Applicants in the recruitment process may be required, where applicable, to successfully complete a role-related assessment(s) and/or a pre-employment screening prior to beginning employment.
Senior Cybersecurity Incident Response Analyst
Cook Children's Health Care SystemCook Children's Health Care System is headquartered in Fort Worth, Texas and is comprised of numerous centers, hospitals, and practices. Since 1918 as a single
Role Description The Cybersecurity Incident Response Analyst Senior (“Senior IR Analyst”) is a member of the Cybersecurity team within the Office of the CISO, focused on protecting sensitive data, applications, and critical systems through effective detection and response to security threats. - Responsible for detecting, responding to, and mitigating security incidents within the organization’s environment to minimize immediate and future risk. - Applies a comprehensive approach across preparedness, mitigation, response, and recovery to ensure the protection of data, preservation of assets, and overall security of information systems. - Conducts in-depth investigations of security events, analyzes response activities, and continuously evaluates and enhances incident response processes. - Identifies, analyzes, and reports potential and active threats across enterprise networks to safeguard systems and sensitive information, leveraging defensive tools, threat intelligence, and data from multiple sources. Qualifications - Bachelor’s degree in computer science, information systems, cybersecurity, or a related field. - Minimum of 5 years of experience in cybersecurity operations, incident response, or security monitoring within an enterprise environment. - Demonstrated hands-on experience investigating and responding to security incidents across network, endpoint, and/or cloud environments. - Experience working with security technologies, such as SIEM, EDR, SOAR, intrusion detection/prevention systems, and case management tools. - Experience performing incident triage, analysis, containment, and remediation activities in a production environment. - Experience developing or executing incident response procedures, playbooks, or runbooks. Benefits - Equal employment opportunities without regard to race, color, religion, sex, age, national origin, physical or mental disability, pregnancy, protected veteran status, genetic information, or any other protected class in accordance with applicable federal laws.
Role Description Would you like to join the Logistics Company for the World? DHL Supply Chain is just that. Become an essential part of everyday life by contributing to an organization that is Connecting People and Improving Lives. We are seeking a strategic and results-oriented Director of Security Operations to lead and advance our security programs across North America (USA, Canada, Puerto Rico). This leadership role is responsible for protecting our people, customers, assets, facilities, transportation networks, and supply chain operations through the development and execution of comprehensive security strategies. The Director of Security Operations drives: - Risk mitigation initiatives - Loss prevention programs - Security investigations - Regulatory compliance - Security governance - Business continuity support while partnering closely with key strategic stakeholders across our company. The Operations Security Director will provide leadership to regional security teams, oversee complex investigations, identify emerging risks and threats, implement corrective actions, and promote a strong culture of security awareness and operational excellence. This role plays a critical part in safeguarding business operations, protecting customer assets, ensuring compliance with corporate and regulatory requirements, and enabling sustainable business growth. Responsibilities - Lead the North American security operations strategy, supporting over multiple sites, transportation operations, associates, customers, and critical supply chain activities. - Direct and oversee investigations involving theft, fraud, workplace misconduct, cargo crime, security incidents, and policy violations, ensuring thorough root cause analysis and effective corrective actions. - Develop security standards, policies, procedures, risk assessments, audits, and compliance programs. - Drive loss prevention initiatives designed to reduce incidents, financial losses, claims, and operational disruptions. - Partner with operations leadership to integrate security best practices into new business implementations, facility start-ups, expansions, and customer solutions. - Provide strategic guidance on physical security, transportation security, supply chain risk management, business continuity, and crisis response. - Lead and develop regional security managers and security professionals while fostering a culture of accountability, collaboration, and continuous improvement. - Strengthen security awareness through training, communication, and employee engagement programs. - Establish and maintain relationships with law enforcement agencies, regulatory bodies, industry associations, and customer security organizations. - Collaborate with HSE, Quality, HR, Labor Relations, Legal, Procurement, Risk & Claims, and Operations to protect people, assets, reputation, and business continuity. - Support customer security requirements, audits, certifications, investigations, and risk mitigation initiatives. - Monitor security trends, emerging threats, regulatory developments, and industry best practices to continuously enhance the security program. - Manage security budgets, vendor relationships, and resource optimization initiatives to maximize operational effectiveness. - Support enterprise-wide and global security initiatives while contributing to the development of long-term security strategy. Qualifications - Strong understanding of logistics, transportation, and supply chain security. - Expertise in risk assessment, threat analysis, loss prevention, investigations, and compliance programs. - Exceptional analytical, problem-solving, and decision-making capabilities. - Proven ability to lead through change, uncertainty, and complex operational challenges. - Excellent communication, presentation, and stakeholder management skills. - Strong leadership and team development capabilities. - Knowledge of local, state, federal, and industry security regulations and standards. Requirements - Bachelor's degree in Criminal Justice, Security Management, Business Administration, Risk Management, or a related field required. - Professional security certifications such as Certified Protection Professional (CPP), preferred. - 7–10 years of progressive experience in corporate security, loss prevention, law enforcement, military service, or related security disciplines, required. - 7–10 years of experience leading investigations, conducting interviews, and managing complex security incidents, preferred. - 5–7 years of leadership experience managing teams in a security or risk management environment, required. - Experience supporting large-scale logistics, transportation, distribution, warehousing, or supply chain operations, preferred. - Experience working with executive leadership, customers, regulatory agencies, and law enforcement partners, preferred. Benefits - Competitive wages - Excellent affordable insurance benefits (including health, dental, vision, and life) - 401K plan - Paid vacation and holidays
