hirly

OSIbeyond

Security Operations Center (SOC) Analyst - Remote

Rockville, Maryland, Remote

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at OSIbeyond first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Mid level
Country
US
Work mode
Remote-friendly
First seen by hirly
2 Oct 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Since 2004, OSIbeyond has delivered managed technology and cybersecurity services on a founding principle: outstanding technical expertise, matched by an exceptional customer experience. Today, that commitment is delivered through OSIbeyond ONE, our integrated technology platform that unifies IT operations, cybersecurity, Microsoft 365, cloud, automation, AI, and expert support into a single, continuously managed environment. The platform is built on a clear operating philosophy: Automation First. AI Enabled. People Powered.

The OSIbeyond Security Operations Center is the cybersecurity engine of that platform. It provides continuous detection, investigation, and response across a diverse portfolio of client environments, including organizations subject to federal compliance frameworks such as CMMC and NIST SP 800-171. The SOC operates on a two-shift, automation-augmented coverage model. Human analysts staff the Day and Evening shifts, and a purpose-built automation layer operates overnight, backed by an on-call analyst, ensuring that every hour of every day is covered by a trained analyst or by an automated response workflow.

The SOC Analyst is the “People Powered” element of security operations. Automation handles the repetitive, high-volume work of enrichment, correlation, and first-response containment, so that the analyst’s time is concentrated on the work that requires human judgment: validating and investigating alerts, leading incident response, advising clients, and continuously improving detection and automation logic. The SOC engineering team is continuously expanding this automation capability, and analysts are expected to contribute to that evolution as active participants rather than passive users.

This position is suited to a technically accomplished security professional who values structure, precision, and accountability. The successful candidate demonstrates sound analytical judgment, disciplined documentation, professionalism in client communication, and a commitment to protecting client environments with the same care they would expect for their own.

ABOUT THE ROLE:

The SOC Analyst monitors, analyzes, and responds to cybersecurity threats across client environments. The analyst operates the SOC’s security tooling, investigates suspicious activity, contains and remediates confirmed incidents, and communicates findings clearly to clients and internal stakeholders.

During each shift the analyst owns the live alert queue, triaging detections from the SIEM, endpoint, identity, and email security platforms; determining scope and severity; and executing or authorizing the appropriate response. Because the SOC operates on a shift model, the analyst is also responsible for the integrity of coverage: conducting structured handoffs at the end of each shift, reviewing existing alerts at the start of the Day shift, and ensuring that no detection, investigation, or client commitment is left without a clear owner.

Beyond day-to-day operations, the analyst performs scheduled vulnerability scanning, conducts root cause analysis for security incidents, and identifies repetitive manual work that should be transitioned to automation. Performance is measured against response times, investigation quality, SLA adherence, documentation standards, and contributions to the continuous improvement of detection and automation.

SCHEDULE & SHIFT MODEL:

The SOC operates a two-shift model with 12-hour shifts. Each analyst is assigned to a fixed shift (Day or Evening) and does not rotate between shift times. The two shifts overlap for six hours (11:00 AM to 5:00 PM), providing a structured handoff window and dual-analyst coverage during peak business hours. Overnight coverage (11:00 PM to 5:00 AM) is provided by the SOC’s Tines automation layer, which performs enrichment, containment, and escalation according to documented playbooks. Escalations that exceed the automation’s authority are routed to the on-call SOC Analyst.

ESSENTIAL DUTIES & RESPONSIBILITIES:

Security Monitoring & Alert Triage (≈50%)

Monitor client environments continuously for security threats using the SIEM, endpoint detection and response, identity protection, and email security platforms

Triage inbound alerts by following the automated priority procedure; determine whether each detection represents a true positive, benign activity, or a tuning opportunity

Respond to alerts where automation is unable to clearly determine legitimacy and/or severity. Work and complete assigned tickets in accordance with documented standard operating procedures and service level commitments

Identify recurring false positives and submit detection-tuning recommendations to the SOC Manager and automation team

Incident Investigation & Response (≈25%)

Investigate security incidents including account compromise, business email compromise, social engineering, malware, and ransomware activity

Through automated means and manual review, analyze servers, workstations, identities, and other assets suspected of compromise and accurately assess the scope and type of the issue

Contain and remediate confirmed threats using approved automation workflows, scripts, policies, playbooks, and platform controls; escalate in accordance with the incident response plan when the situation exceeds the analyst’s authority or expertise

Provide accurate, timely, and professionally written incident communications to designated client points of contact and internal stakeholders with the assistance of the SOC Manager or CISO

Vulnerability Management & Security Posture (≈10%)

Perform regularly scheduled vulnerability scanning across client environmentsSupport client compliance objectives, including CMMC and NIST SP 800-171 requirements, by producing the monitoring evidence, logs, and reports required by those frameworks

Contribute to periodic client security reviews with clear, data-supported observations

Automation Oversight & Continuous Improvement (≈15%)

Review the overnight Tines automation log at the start of the Day shift, confirm low confidence actions were appropriate, and remediate or escalate any exceptions

While on call, respond to overnight escalations from the automation layer, take ownership of the incident, and document all actions taken for review at the start of the Day shift

Identify repetitive manual investigation and response steps and submit them to the automation team as candidates for new automations or expanded playbooks

Identify repetitive “false positives” for the SOC Manager to address

Test and provide structured feedback on new detections and automation workflows before they are placed into production

Track and document all work in the ticketing system with detail sufficient for a peer to resume the work without additional context

General Responsibilities

Provide high-quality written and verbal customer service in every client interaction

Meet all key performance indicators and notify the SOC Manager promptly when workload or circumstances place a KPI at risk

Recognize when an assignment should be escalated and escalate without delay

Support peers across both shifts and contribute to a collaborative, accountable team culture

Perform other duties as assigned

SUCCESS METRICS:

Mean time to acknowledge and mean time to respond for alerts during the assigned shift

Mean time to contain and mean time to resolve for confirmed incidents

KPI adherence across all assigned tickets

Escalation accuracy: incidents escalated at the appropriate severity and stage, with complete supporting documentation

Quality of shift handoffs, measured by open items with a clear owner and no unattended investigations at shift change

Accuracy of automated-action validation and exceptions correctly identified in the overnight automation review

On-call responsiveness: acknowledgment and response times for overnight escalations during assigned on-call weeks

Original posting on OSIbeyond's site ↗

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job