SOC Architect
Openkyber
Location: Austin, TX, (Onsite)
Position Type: Contract
Interview Mode: MS Teams
Knowledge, Skills, and Abilities
Knowledge of: Cybersecurity Operations Center (CSOC/SOC) operations and best practices. Security incident triage, analysis, investigation, and escalation procedures. Security monitoring technologies, including SIEM, EDR/XDR, IDS/IPS, firewalls, endpoint security solutions, and cloud security platforms. Common cyber threats, attack vectors, malware, phishing campaigns, insider threats, and advanced persistent threat (APT) techniques. Threat intelligence concepts, indicators of compromise (IOCs), indicators of attack (IOAs), and MITRE ATT&CK methodologies. Windows, Linux, networking protocols, Active Directory, Microsoft Entra ID, cloud environments, and enterprise security controls. Incident response lifecycle and cybersecurity frameworks such as NIST Cybersecurity Framework, NIST Incident Response guidance, and PICERL.
Skill in: Security event analysis and threat triage. Correlating and interpreting data from multiple cybersecurity tools. Investigating suspicious activity and identifying indicators of compromise. Using SIEM, EDR/XDR, threat intelligence, vulnerability management, and case management platforms. Producing clear documentation, incident reports, and technical communications. Prioritizing and managing multiple investigations in a fast-paced operational environment for a large organization. Knowledge of and experience with query languages such as KQL, Lucene, SPL, ESQL, etc. Knowledge of and experience with scripting languages such as PowerShell, Python, Bash, etc.
Ability to: Analyze complex security events and distinguish legitimate threats from false positives. Make risk-based decisions during incident investigations. Execute established incident response and escalation procedures. Collaborate effectively with security engineers, incident responders, system administrators, CISO leadership, and business stakeholders. Communicate technical information clearly to both technical and non-technical audiences. Work independently and as part of a 24x7 cybersecurity operations team.
Preferred Education and CertificationsGraduation from an accredited four-year college or university with major coursework in cybersecurity, information security, computer science, computer information systems, management information systems, or a related field is preferred. Relevant education and experience may be substituted for one another. One or more of the following certifications are preferred: CompTIA Security+, GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), Certified SOC Analyst (CSA), Microsoft Cybersecurity Analyst (SC-200), Other GIAC or SOC-related certifications.
Required QualificationsMinimum of five (5) years of experience in cybersecurity operations, security monitoring, incident response, threat detection, security investigations, or related cybersecurity disciplines. Experience working with one or more of the following technologies: SIEM platforms (NetWitness, Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm, etc.) Microsoft Security (Microsoft 365 Defender XDR, Microsoft Sentinel) Endpoint Detection and Response (Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, etc.) IDS/IPS technologies (Trellix/FireEye, Corelight) Threat intelligence platforms (VirusTotal, Google Threat Intelligence, Cisco Talos, Recorded Future, MISP) Vulnerability management tools (Tenable, Qualys, Rapid7) Email security platforms (IronPort ESA, Abnormal.ai, Proofpoint) Cloud security monitoring solutions (Google Wiz, MDCA, Cortex Cloud, Sysdig) Secure Access Service Edge (Zscaler, Prisma, Netskope) Experience triaging security alerts, analyzing security events, and documenting incident investigations. Experience with cybersecurity frameworks, incident response processes, and threat detection methodologies.
Work Expectations Participate in incident response, escalation, and after-action review activities as needed. Support enterprise security monitoring for systems that process, store, or transmit sensitive information. Follow HHSC policies, procedures, standards, and applicable state and federal security requirements. Maintain accurate operational documentation, investigation notes, metrics, and leadership-ready summaries. Must be able to provide support outside of normal business hours during high-priority security incidents, as approved by the SOC Manager.
II. CANDIDATE SKILLS AND QUALIFICATIONSMinimum Requirements: Candidates that do not meet or exceed the minimum stated requirements (skills/experience) will be displayed to customers but may not be chosen for this opportunity.
- 3 Required Experience triaging security alerts
- 3 Required Experience analyzing security events
- 3 Required Experience documenting incident investigations
- 3 Required Experience with cybersecurity frameworks
- 3 Required Experience with incident response processes
- 3 Required Experience with threat detection methodologies
- 3 Required Experience in cybersecurity operations
- 3 Required Experience in security monitoring
- 3 Required Experience in incident response
- 3 Required Experience in threat detection
- 3 Required Experience in security investigations
- 3 Required Experience in related cybersecurity disciplines
- 5 Preferred Please See Job Description Section for more specific Preferred and Required Skills.
For applications and inquiries, contact:View email address on us.fitly.work
- Enterprise Network Engineering Design, implement, and support highly available network infrastructure across on-prem data centers, private cloud, AWS, and Azure. Engineer resilient Layer 2/Layer 3 architectures including routing, switching, BGP, OSPF, VXLAN/EVPN, ...SuggestedRemote work
- The Arkansas Democrat-Gazette seeks a versatile wire editor and page designer to join our sports desk in Little Rock. We are looking for a meticulous professional who is capable of working at a fast pace and wearing many hats, some nights editing national sports stories...SuggestedNight shift
- Job Description Job Description Who We Are Atwell, LLC is a bold leader in the consulting, engineering, and construction services industry, delivering a broad range of creative solutions to clients in the real estate & land development, and energy markets. We have...SuggestedLocal areaRemote work
- ...audits, documentation, and technical reviews Collaboration & Leadership Work closely with business stakeholders, project managers, architects, and other developers Provide technical guidance and mentorship to junior developers and citizen developers Participate in...SuggestedTemporary workRemote work
$90 - $100 per hour
SAP Retrofit Management Specialist (Remote) We are looking for an SAP Retrofit Management Specialist for a global aerospace company. In this role, you will manage SAP retrofit activities across multi-track landscapes, ensuring transport changes are synchronized correctly...SuggestedContract workRemote work10 hours per weekDay shift- ...Customer Engineer, Security Engineer, Implementation Engineer, Onboarding Engineer, Consultant, Technical Support Engineer, Solutions Architect, and/or Systems Engineer. ~ Layers and protocols of the OSI model, such as TCP/IP, TLS, DNS, ~ Deep understanding of...Contract workWork experience placementRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to SOC Architect. Be the first to apply!

