Security Operations Center (SOC) Analyst - Remote
OSibeyond
Since 2004, OSIbeyond has delivered managed technology and cybersecurity services on a founding principle: outstanding technical expertise, matched by an exceptional customer experience. Today, that commitment is delivered through OSIbeyond ONE, our integrated technology platform that unifies IT operations, cybersecurity, Microsoft 365, cloud, automation, AI, and expert support into a single, continuously managed environment. The platform is built on a clear operating philosophy: Automation First. AI Enabled. People Powered.The OSIbeyond Security Operations Center is the cybersecurity engine of that platform. It provides continuous detection, investigation, and response across a diverse portfolio of client environments, including organizations subject to federal compliance frameworks such as CMMC and NIST SP 800-171. The SOC operates on a two-shift, automation-augmented coverage model. Human analysts staff the Day and Evening shifts, and a purpose-built automation layer operates overnight, backed by an on-call analyst, ensuring that every hour of every day is covered by a trained analyst or by an automated response workflow.The SOC Analyst is the "People Powered" element of security operations. Automation handles the repetitive, high-volume work of enrichment, correlation, and first-response containment, so that the analyst's time is concentrated on the work that requires human judgment: validating and investigating alerts, leading incident response, advising clients, and continuously improving detection and automation logic. The SOC engineering team is continuously expanding this automation capability, and analysts are expected to contribute to that evolution as active participants rather than passive users.This position is suited to a technically accomplished security professional who values structure, precision, and accountability. The successful candidate demonstrates sound analytical judgment, disciplined documentation, professionalism in client communication, and a commitment to protecting client environments with the same care they would expect for their own.ABOUT THE ROLEThe SOC Analyst monitors, analyzes, and responds to cybersecurity threats across client environments. The analyst operates the SOC's security tooling, investigates suspicious activity, contains and remediates confirmed incidents, and communicates findings clearly to clients and internal stakeholders.During each shift the analyst owns the live alert queue, triaging detections from the SIEM, endpoint, identity, and email security platforms; determining scope and severity; and executing or authorizing the appropriate response. Because the SOC operates on a shift model, the analyst is also responsible for the integrity of coverage: conducting structured handoffs at the end of each shift, reviewing existing alerts at the start of the Day shift, and ensuring that no detection, investigation, or client commitment is left without a clear owner.Beyond day-to-day operations, the analyst performs scheduled vulnerability scanning, conducts root cause analysis for security incidents, and identifies repetitive manual work that should be transitioned to automation. Performance is measured against response times, investigation quality, SLA adherence, documentation standards, and contributions to the continuous improvement of detection and automation.SCHEDULE & SHIFT MODELThe SOC operates a two-shift model with 12-hour shifts. Each analyst is assigned to a fixed shift (Day or Evening) and does not rotate between shift times. The two shifts overlap for six hours (11:00 AM to 5:00 PM), providing a structured handoff window and dual-analyst coverage during peak business hours. Overnight coverage (11:00 PM to 5:00 AM) is provided by the SOC's Tines automation layer, which performs enrichment, containment, and escalation according to documented playbooks. Escalations that exceed the automation's authority are routed to the on-call SOC Analyst.ESSENTIAL DUTIES & RESPONSIBILITIESSecurity Monitoring & Alert Triage (˜50%)Monitor client environments continuously for security threats using the SIEM, endpoint detection and response, identity protection, and email security platformsTriage inbound alerts by following the automated priority procedure; determine whether each detection represents a true positive, benign activity, or a tuning opportunityRespond to alerts where automation is unable to clearly determine legitimacy and/or severity. Work and complete assigned tickets in accordance with documented standard operating procedures and service level commitmentsIdentify recurring false positives and submit detection-tuning recommendations to the SOC Manager and automation teamIncident Investigation & Response (˜25%)Investigate security incidents including account compromise, business email compromise, social engineering, malware, and ransomware activityThrough automated means and manual review, analyze servers, workstations, identities, and other assets suspected of compromise and accurately assess the scope and type of the issueContain and remediate confirmed threats using approved automation workflows, scripts, policies, playbooks, and platform controls; accelerate in accordance with the incident response plan when the situation exceeds the analyst's authority or expertiseProvide accurate, timely, and professionally written incident communications to designated client points of contact and internal stakeholders with the assistance of the SOC Manager or CISOVulnerability Management & Security Posture (˜10%)Perform regularly scheduled vulnerability scanning across client environmentsSupport client compliance objectives, including CMMC and NIST SP 800-171 requirements, by producing the monitoring evidence, logs, and reports required by those frameworksContribute to periodic client security reviews with clear, data-supported observationsAutomation Oversight & Continuous Improvement (˜15%)Review the overnight Tines automation log at the start of the Day shift, confirm low confidence actions were appropriate, and remediate or elevate any exceptionsWhile on call, respond to overnight escalations from the automation layer, take ownership of the incident, and document all actions taken for review at the start of the Day shiftIdentify repetitive manual investigation and response steps and submit them to the automation team as candidates for new automations or expanded playbooksIdentify repetitive "false positives" for the SOC Manager to addressTest and provide structured feedback on new detections and automation workflows before they are placed into productionTrack and document all work in the ticketing system with detail sufficient for a peer to resume the work without additional contextGeneral ResponsibilitiesProvide high-quality written and verbal customer service in every client interactionMeet all key performance indicators and notify the SOC Manager promptly when workload or circumstances place a KPI at riskRecognize when an assignment should be escalated and escalated without delaySupport peers across both shifts and contribute to a collaborative, accountable team culturePerform other duties as assignedSUCCESS METRICSMean time to acknowledge and mean time to respond for alerts during the assigned shiftMean time to contain and mean time to resolve for confirmed incidentsKPI adherence across all assigned ticketsEscalation accuracy: incidents escalated at the appropriate severity and stage, with complete supporting documentationQuality of shift handoffs, measured by open items with a clear owner and no unattended investigations at shift changeAccuracy of automated-action validation and exceptions correctly identified in the overnight automation reviewOn-call responsiveness: acknowledgment and response times for overnight escalations during assigned on-call weeksDetection tuning and automation candidates submitted and adoptedDocumentation quality and completeness of ticket notes, incident reports, and root cause analysesClient satisfaction with incident communications and security reviewsSECURITY RESPONSIBILITIESComplete training for and maintain awareness of cybersecurity risks, including insider threat, and the appropriate handling of CUI and other regulated dataTreat client data and OSIbeyond data as sensitive, and do not disclose, release, or otherwise transfer it outside of OSIbeyond or client environments without written permissionFollow cybersecurity requirements as described in the Employee Handbook and other OSIbeyond policiesImmediately follow incident response procedures when a security incident or concern is identifiedAssist with the escorting or monitoring of visitors when working onsiteMonitor alerts from the SIEM and related security platforms, conduct vulnerability scans, and review and update logged eventsQUALIFICATIONSExperienceTwo or more years of experience in security operations, incident response, or systems administration with a demonstrable security focus; managed service provider experience is strongly preferredDemonstrated experience investigating and responding to identity, endpoint, and email-based threats in Microsoft 365 environmentsSecurity Operations SkillsWorking knowledge of SIEM operations, log analysis, and alert triage methodologyUnderstanding of common attack techniques and the MITRE ATT&CK framework, and the ability to map observed activity to adversary behaviorFamiliarity with endpoint detection and response, identity protection, and email security controls and their remediation actionsAbility to perform disciplined, well-documented investigationsSystems & Network KnowledgeSolid understanding of Microsoft 365 and Entra ID administration, including conditional access, authentication methods, and audit loggingWorking knowledge of Windows server and workstation operating systems, Active Directory, and core networking concepts (TCP/IP, DNS, firewall, VPN)Familiarity with vulnerability scanning platforms and remediation workflowsAutomation & Operational SkillsComfort operating within an automation-first environment, including validating and troubleshooting the output of automated playbooks (Tines or comparable SOAR tooling)Basic scripting or query proficiency (PowerShell, KQL, or similar) sufficient to enrich investigations and validate dataDisciplined ticket hygiene and documentation habits; ability to write clear, professional client-facing communicationsReliability and self-management appropriate to a remote, shift-based role with defined coverage responsibilitiesAdditional Desirable QualificationsExperience supporting clients subject to CMMC, NIST SP 800-171, or similar regulatory frameworksPrior experience contributing to detection engineering or automation playbook developmentExperience in a 24x7 or shift-based security operations environmentKNOWLEDGE & CERTIFICATIONSTooling Environment: SIEM and extended detection and response platforms; Sentinel One and Blumira; Entra ID identity protection; Tines security automation; vulnerability scanning platform; Autotask professional services automation (ticketing); Microsoft Teams for internal collaboration.Required Certifications (or attainment within the first six months)CompTIA Security+CompTIA Network+Preferred CertificationsCompTIA SecurityX (CASP+) or other DoD 8140 Level II certificationPosition:Location – Remote from the United States, must be willing to work EST hoursShift Schedule: 11:00am-11:00pm ESTEmployment Type- Full timeBenefits:Medical Insurance- OSIbeyond pays 75% of the premium for the Employee's base medical planVision and Dental Insurance- OSIbeyond pays 75% of the premium for the Employee's plansLife Insurance- OSIbeyond pays 100% of the premium for the Employee's plansShort Term Disability Insurance- OSIbeyond pays 100% of the premium for the Employee's plans401K- OSIbeyond matches up to 4%PTO/Holidays - 9 paid Holidays and accrual based PTO which increases with tenure, new hires start out with 2 weeks.J-18808-Ljbffr
- ...Native owned corporation, our work helps secure an enduring future for our... ...employer and Certified Great Place to Work™ SOC Analyst Location: Remote | Night and Weekend Shifts Required Active... ...supports enterprise cybersecurity operations, including Risk Management Framework...Remote workFor contractorsNight shiftWeekend work
$62k - $141k
Incident Response Analyst, MidThe Opportunity:Serve as a key member of a 24x7x365 Security Operations Center(SOC) and incident response team, responsible for continuous monitoring... ...to have their cameras on during meetings.Remote: If this position is listed as remote, there...Remote workFull timeContract workPart timeLocal area$85k - $115k
...Light has an opening for a CND Analyst - SOC supporting the Army National... ...contract in support of the operation, modernization, expansion,... ...enterprise systems, defend against security breaches, and identify,... ...SOC operations to that remote location.Provide technical reports...Remote workContract workWork experience placementWorldwideRelocationShift work- ...Intel Community.Location: Remote 95% of the time. Will... ...to change).Who are you?Security-cleared Professional:... ...developing, and maintaining SOC oriented services and... ...from engineering, operations, and managementTechnologies... ...taken by the SOC analyst teamPrepare, provide, and...Remote workTemporary workWork at office
$120k - $135k
...a Senior Incident Response Analyst to join our team in support... ...government program. As part of the Security Operations Center, you will help monitor,... ...are eligible to work fully remote. RESPONSIBILITIES: Lead... ...automation scripts to strengthen SOC monitoring capabilities....Remote workPermanent employmentContract work2 days per week$100k - $125k
SOC Analyst Hybrid-- 2 days a week onside in Bethesda, MDThe Security Operations Center Analyst will be responsible for monitoring and analyzing security threats and implementing appropriate countermeasures to protect the organization's information assets. Key Responsibilities...2 days per week$131.3k - $237.35k
...to our communities, and operate sustainable. Everything... ...Senior Incident Response Analyst to support the DHS CISA... ...Department of Homeland Security (DHS), Security Operations Center (SOC) Support Services is a US... ...with relevant laws. #Remote REQNUMBER: R-00192687...Remote workLocal areaImmediate startFlexible hours- Zscaler is seeking a Senior SOC Analyst to join our Enterprise Security team in a remote capacity. You will monitor, detect, and analyze security incidents to protect our global digital assets and respond as the first line of defense. You will collaborate with global teams...Remote job
- ...A leading cybersecurity firm in Washington, D.C. is seeking a Security Operations Center (SOC) Analyst. In this role, you will monitor and analyze security incidents, responding to threats and securing sensitive data. You will perform vulnerability assessments, collaborate...
- New York Life seeks a seasoned SOC Analyst to monitor, detect, and respond to security incidents across hybrid and cloud environments. You’ll use SIEM/EDR/XDR... ...or related field and have 3-4 years in security operations, with cloud experience across AWS and GCP. #J-1880...Remote job
- ...brightest minds in cyber security who are passionate... ...think adding a Security Analyst L1 will up our cyber game... ...our clients and grow our operations. In return, you will be... ...Operations Centre (SOC) uses a combination of... ...Arrangement This is a remote position open to candidates...Remote workImmediate startFlexible hours
- LPL Financial is seeking an Information Security Analyst II to join the Security Operations Center in a hybrid role based in Tempe, AZ. You will monitor, triage,... ...security platforms. The role requires 2+ years in a SOC, knowledge of Internet protocols, and relevant...
- Weiatech, LLC is seeking a SOC Tier 1 Analyst to act as the first line of defense within the Security Operations Center. The role involves continuous monitoring of security events, alert triage, and documenting findings while following established procedures. The ideal...
- ...DescriptionJob DescriptionJob Title: SOC AnalystLocation: US-MD-Crownsville (1... ...CompTIA CySA+ certification / or a CompTIA Security+ (or other relevant IAT Level II/III... ....Client is seeking a Security Operations Center (SOC) Analyst with hands-on experience monitoring,...Shift workNight shiftDay shiftAfternoon shift
- ...Leading the Security Operations Center (SOC) team, the full-time remote Information Security Analyst III will monitor a complex enterprise technology ecosystem, detect and investigate security events, and respond to incidents to safeguard institutional information and...Remote workFull time
$106.68k - $170.73k
...purpose. Since 1932, our people-centered strategy has defined us —... ...'ll have the option to work remotely in the following states:... ...opportunity The Information Security Analyst III is the senior lead for the Security Operations Center (SOC) team and is responsible for...Remote workFull timeWorldwide$94.49k - $131.16k
...SummaryThe Senior Information Security Analyst is responsible for... ...relationships with our security operations vendors and providing... ...strategies, and SOC (Security Operations Center) operations. Cloud Security... ...arrangement comprised of remote and in-office work, the requirement...Remote workFull timeWork at officeRelocationVisa sponsorshipRelocation package- ...Job Description Job Description CyberLinx Solutions, LLC is seeking a SOC Analyst (Tier 2) / Security Incident Investigator to join our Security Operations Center(SOC). This role is responsible for conducting in-depth investigations of security alerts escalated by...
- ...The Opportunity As a Mastery Level Security Operations Center (SOC) analyst you’ll have an opportunity to be part of a growing team of highly technical... ...a strong legacy and a future-focused mindset LI-RK1 LI-Remote MassMutual is an equal employment opportunity employer....Remote workTemporary work
- ...Senior Information Security Analyst Protect the business.... ...to strengthen security operations, application security,... ...based Network Operations Centers operate 24/7, and our... ...in coordination with SOC providers Serve as... ...office or as a fully remote role, based on business...Remote workFor contractorsWork at office
$18.77 per hour
...corporation, our work helps secure an enduring future for our shareholders... ...Continuous Vetting (CV) Analyst The Continuous Vetting (... ...the Case Processing Operations Center (CPOC) contract within the Defense... ...be performed primarily in a remote capacity. If the employee...Remote workHourly payContract workFor contractorsWork at officeFlexible hoursAfternoon shift- ...VPN, DNS, DHCP, proxy, email security, cloud audit logs, API gateways... ..., application logs, and operating system logs.Develop detections... ...mentoring to Tier 1 and Tier 2 analysts.Support management with reporting... ...hands-on Security Operations Center experience.Minimum 4 years...Full timeWork at office
- ...provides oversight to information and cyber security risk by maintaining and improving... ...security risks inherent in the Branch Operations. IRG is directly involved in all... ...Role Overview: The Security Operations Center (SOC) Analyst is responsible for monitoring, detecting...Work at officeWork from homeFlexible hours2 days per week
$70 - $95 per hour
...This role focuses on enhancing security operations through the application of... ...judgment and expertise in SOC environments. As a SOC Investigation... ...Mentor or support other analysts where applicable,... ...certifications. Work Terms Remote position with hourly compensation...Remote workHourly pay$101.7k
...including, but not limited to, DCGS, Air Operations Center (AOC) intelligence, targeting, analysis... ...analysis, imagery intelligence, remote sensing analysis, data science, and space... ...that their work contributes to national security and global stability. If you are looking...Remote workTemporary workFor contractorsFlexible hours- ...of Europe’s safest and most secure platforms that powers modern... ...Headquartered in Austria but operating across Europe, our products are... ...digital assets. As a Senior SOC Analyst, you'll play a critical role... ...combining onsite collaboration and remote work, with an additional 25...Remote workFull timeInternshipWork at officeWorldwideRelocation packageShift work
- ...are currently seeking a Data Center Ops Senior Analyst to join our team in Bekasi,... ...should know the basic Operations in Data Center running environment... ...-scale AI, cloud, security, connectivity, data centers... ...While many positions offer remote or hybrid work options, these...Remote workWork at officeFlexible hoursShift workRotating shiftDay shiftAfternoon shift
- ...Job Description Job Description Description: The Security Operations Center (SOC) Analyst I provides real time security monitoring and threat hunting in our Security Operations Center. This individual will have the opportunity to work with customers across many industries...Immediate start
- ...Job Description Job Description CyberLinx Solutions is seeking a SOC Analyst (Tier 1) / Security Monitoring Analyst to support our Security Operations Center (SOC). This role is responsible for continuous monitoring of security alerts generated by SIEM, provide continuous...
- ...This Role The DC Office of the Chief Technology Officer (OCTO) is seeking a Tier 3 SOC Analyst to provide advanced technical and analytical oversight of a Security Operations Center team that monitors, detects, analyzes, remediates, and reports on cybersecurity...Work at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Operations Center (SOC) Analyst - Remote. Be the first to apply!
- security specialist Rockville, MD
- security consultant Rockville, MD
- network security consultant Rockville, MD
- security coordinator Rockville, MD
- security advisor Rockville, MD
- operations research Rockville, MD
- dental operations Rockville, MD
- lab operations Rockville, MD
- analyst sales operations Rockville, MD
- marketing operations Rockville, MD





