The posting
Voxidea is seeking an experienced and highly motivated SOC Analyst to join our IT and Security Operations team. This role is responsible for monitoring, triaging, investigating, and responding to security events across endpoints, identity, cloud, network, and other enterprise systems.
The SOC Analyst will work closely with our Managed Security Service Provider (MSSP) and internal IT team to validate alerts, investigate potential threats, coordinate containment and remediation, drive ticket resolution, and continuously improve our security controls, policies, and operational processes.
This is an operator-level role requiring hands-on experience in a mature security environment. The ideal candidate can independently investigate security events, work across multiple security technologies, identify recurring risks and alert noise, recommend improvements, and clearly communicate findings to IT leadership.
Key Responsibilities
- Triage, investigate, and respond to security alerts from MSSPs, SIEMs, XDR/EDR platforms, firewalls, identity systems, and other security tooling.
- Work directly with the MSSP to validate alerts, investigate escalations, request and review evidence, and coordinate appropriate response actions.
- Perform hands-on investigation using technologies such as SentinelOne, Microsoft Defender, Microsoft 365, SIEM platforms, and Cisco security/networking technologies.
- Validate detections quickly and accurately by determining:
- False positive vs. true positive
- Scope and severity of impact
- Affected users, endpoints, systems, and accounts
- Indicators of compromise
- Required containment and remediation actions
- Own security tickets end-to-end, including categorization, prioritization, investigation, escalation, documentation, remediation, and closure.
- Coordinate containment actions with IT, including endpoint isolation, account/session actions, blocking indicators, access changes, and other remediation measures.
- Investigate suspicious authentication, mailbox, endpoint, network, and cloud activity.
- Correlate information across multiple security platforms to establish an accurate incident timeline and determine root cause.
- Monitor and analyze trends in alerts and incidents and identify opportunities to reduce recurring security noise.
- Recommend and implement security control, configuration, and policy improvements based on observed threats and operational trends.
- Participate in tuning detection rules, security policies, access controls, endpoint configurations, and other security controls.
- Maintain and improve SOC playbooks, incident-response procedures, and security documentation.
- Support security incident response, evidence collection, and preservation procedures when required.
- Produce weekly and monthly security reporting for the IT Director, including:
- Incident summaries
- Alert volume and categories
- Response and resolution times
- Significant security events
- Recurring alert trends
- Control gaps
- Recommended improvements
- Support continuous improvement initiatives involving endpoint telemetry, monitoring, detection, response, and security operations.
Requirements
Required Experience and Skills
- 3–5+ years of professional experience in a SOC Analyst, Security Operations, Security Monitoring, Incident Response, or closely related cybersecurity role.
- Demonstrated experience working in a medium-to-large enterprise environment, MSSP, managed security environment, or similarly complex infrastructure.
- Hands-on experience with Cisco security and networking technologies is required.
- Hands-on experience with SIEM, EDR/XDR, firewall, identity, and network security technologies.
- Demonstrated hands-on experience with SentinelOne and/or Microsoft Defender or comparable enterprise EDR platforms.
- Experience working directly with an MSSP, including handling escalations, investigating alerts, requesting/reviewing evidence, and coordinating remediation.
- Experience triaging alerts and working security tickets end-to-end, rather than simply monitoring dashboards or forwarding alerts.
- Strong understanding of:
- Endpoint Detection and Response (EDR)
- Security Information and Event Management (SIEM)
- Identity and access security
- Network security
- Common attack patterns and indicators of compromise
- Incident response and containment
- Security event correlation
- Experience investigating suspicious authentication, endpoint, network, email, and cloud activity.
- Ability to independently determine whether an alert represents a false positive, suspicious activity, or a confirmed security incident.
- Experience recommending or implementing security control and configuration changes based on incident findings and recurring alert patterns.
- Strong written documentation skills, including the ability to create clear incident timelines, investigation notes, evidence summaries, and remediation records.
- Ability to communicate technical security findings and risk in clear, business-oriented language to IT leadership and non-security stakeholders.
- Strong analytical and problem-solving skills with the ability to work independently.
Certifications
At least one of the following certifications is required, with active certifications or certifications earned within the last three years preferred:
- CompTIA Security+
- CompTIA CySA+
- Microsoft SC-200 – Security Operations Analyst
- GIAC certification relevant to security operations
- Equivalent recognized cybersecurity certification
Preferred Qualifications
- Advanced hands-on experience with Cisco security technologies and enterprise networking environments.
- Experience with Cisco Secure Firewall, Cisco security platforms, or comparable enterprise Cisco security solutions.
- Direct experience with SentinelOne alert investigation, threat analysis, containment, and response workflows.
- Strong experience with Microsoft Defender and Microsoft 365 security.
- Experience working alongside an MSSP/SOC provider in a multi-tier escalation environment.
- Experience supporting organizations with hundreds or thousands of users/endpoints.
- Experience working across Tier 1, Tier 2, and/or Tier 3 security operations.
- Familiarity with professional services or law firm environments where confidentiality, data protection, and evidence preservation are critical.
- Experience drafting or updating security policies, standards, playbooks, and incident-response procedures.
- Experience improving detection logic, reducing alert noise, and optimizing security tooling.
- Scripting and automation experience with PowerShell, Python, or similar technologies.
- Experience with security governance, compliance, or risk management.
- Familiarity with emerging AI security, governance, and data-protection considerations.
Tools and Environment
The SOC Analyst will work across a range of enterprise security technologies, including:
- SentinelOne
- Microsoft Defender
- Microsoft 365 security tools
- SIEM platforms
- Cisco security and networking technologies
- Firewalls and network security controls
- Identity and access-management systems
- MSSP/SOC monitoring platforms
- Endpoint telemetry and EDR/XDR workflows
- Security ticketing and documentation systems
Benefits
- Biweekly payments, free of deductions from our end
- Long-term work relationship perspective
- Fully remote job, 40 hours per week, with 2 days off
- Paid vacation time and recognition of US holidays
- Mental health support and work-life balance culture
- Collaborative and inclusive work environment



