Overview
Skills
Job Details
Role Name: SOC Analyst
Location: Hybrid role with 2 days a week onsite in Sandy Springs, GA, USA
Duration: 6+ Months
L2 support, 8x5 EST. Preferably based in Atlanta and goes to client site 2x per week. Open to remote for the right person.
Technical Skills
o SIEM Tools Experience (e.g., Splunk, QRadar, LogRhythm, Elastic Stack) - Google SecOps (formerly Chronicle) experience a plus
o Intrusion Detection and Prevention Systems (IDS/IPS)
o Endpoint Detection and Response (EDR) Tools (e.g., MS Defender, CrowdStrike, etc.)
o Firewall, Proxy, and Network Monitoring
o Incident Response and Handling
o Malware Analysis and Reverse Engineering (basic for analysts, advanced for engineers)
o Vulnerability Management Tools (e.g., Nessus, Qualys)
o Familiarity with MITRE Telecommunication&CK Framework
o Packet Analysis Tools (e.g., Wireshark, tcpdump)
o Log Analysis and Correlation
Knowledge Areas
o Understanding of TCP/IP, DNS, HTTP/S, and other protocols
o Security Best Practices and Regulatory Compliance (e.g., HIPAA, PCI-DSS, GDPR)
o Threat Hunting Techniques
o Cyber Threat Intelligence (CTI) Concepts
o Kill Chain and Incident Lifecycle Knowledge
o Cloud Security (AWS, Azure, Google Cloud Platform) increasingly important
Experience
o Hands-on Security Incident Triage and Escalation
o 24/7 On-Call or Rotational SOC Environments
o Playbook Development and Automation
o Scripting/Automation Skills (e.g., Python, Bash, PowerShell)
o Developing/Improving Detection Rules and Use Cases
o Interfacing with Tier-3 Analysts or Threat Intelligence Teams
o Participation in Red/Blue/Purple Team Exercises
Soft Skills
o Strong Analytical and Problem-Solving Skills
o Clear and Concise Communication (written and verbal)
o Collaboration Across Teams (IT, Risk, Compliance)
o Calm Under Pressure and Crisis Management
o Curiosity and Eagerness to Learn Continuously
Certifications (Preferred or Required)
o CompTIA Security+
o GIAC Certifications (e.g., GCIH, GCIA, GCFA)
o Certified SOC Analyst (CSA)
o Certified Ethical Hacker (CEH)
o CISSP or CISM, etc. a plus