Jobs · Analyst

Remote Role || Security Analyst - Project Lead || Columbia, SC

Cyber Focus AI · United States · 1 mo ago
RemoteRemoteAnalystFull-time

Cyber Focus AI’s mission is to help cybersecurity professionals discover cutting-edge opportunities in their field.

About the role

This 12-month contract position will work as a Tier 2 SOC Analyst for the Division of Information Security, focusing on security monitoring, threat detection, security incident response, and security investigations. A key focus is engaging directly with state agencies to promote, support, and improve adoption of centralized security services.

Preference will be given to candidates who can work onsite as needed over hybrid or full-time remote.

Responsibilities

  • Continuously review and correlate security event data across SIEM, EDR, IDS/IPS, and threat intelligence sources to identify complex attack patterns, emerging threats, and security incidents.
  • Perform deep-dive analysis of suspicious activity, validate incidents, determine root cause and impact, and escalate critical incidents with detailed context to Tier 3 as required.
  • Create detailed incident reports, timelines, and post-incident summaries; contribute to lessons-learned documentation and recommendations for remediation and preventative measures.
  • Investigate user-reported phishing, malware infections, and potential policy violations; advise users and internal/external teams on containment and recovery actions.
  • Recommend updates to SOC playbooks and workflows based on real-world investigations; fine-tune detection rules, alert thresholds, and correlation logic to reduce false positives and improve threat coverage.
  • Collaborate with engineering teams to ensure monitoring tools are properly configured and tuned.
  • Integrate new threat intelligence feeds into workflows and proactively hunt for threats using up-to-date tactics, techniques, and procedures (TTPs).
  • Serve as a customer-facing subject-matter expert, demonstrating capabilities and resolving issues to promote the value of DIS services.
  • Document processes, runbooks, and troubleshooting steps related to SOC operations.
  • Coordinate with engineering, SOC, and agency staff as needed to meet goals.
  • Perform other duties as needed.

Requirements

  • 2+ years of experience with security monitoring and incident response.
  • 2+ years of experience with the MITRE ATT&CK framework.
  • 2+ years of experience with dashboard creation and reporting.

Preferred Skills

  • Experience with the Palo Alto Cortex XSIAM/XDR platform.
  • Knowledge of Linux network administration and network design.
  • Experience in administration of firewalls, VPN technology, Active Directory, and Intrusion Detection/Prevention systems.

Similar jobs

Security Analyst | Remote

Crossing HurdlesUnited States· 2 days ago
RemoteInformation Technology$37/hrapply on candidateportal.ceipal.com