SOC / Blue Team
SOC Analyst (L1–L2)
Triage alerts, hunt weak signals, and escalate with context — not ticket spam. Blue team craft for the street desk.
- Type
- Full-time
- Location
- Remote / hybrid
- Posted
- 2026-10-01
Responsibilities
- Monitor SIEM / EDR alerts and classify true vs false positives
- Run basic investigations: timeline, IOCs, containment notes
- Document playbooks and handoffs for L2/IR
- Stay ethical — no unauthorized scanning of third parties
Requirements
- Familiarity with Windows/Linux logs and common attack patterns
- Experience with at least one SIEM or EDR console
- Calm under noisy alert volumes
- Shift flexibility (including some weekends/on-call as needed)
Nice to have
- CompTIA Security+, CySA+, or similar
- Scripting for enrichment (Python/SOAR basics)
- Threat intel feed curation