Job role
The SOC Engineer I role supports security monitoring, alert triage, log review, and clear incident handoff. This is a remote opening for candidates who are disciplined with details, comfortable working from evidence, and serious about building cybersecurity operations fundamentals. The role is expected to keep investigations organized, avoid assumptions, and escalate security concerns with useful context.
Role responsibilities
- Review security alerts from approved monitoring tools and record clear triage notes.
- Validate alert context using available logs, timestamps, users, hosts, and network indicators.
- Classify common events such as phishing, malware, suspicious login, endpoint alert, and policy violation.
- Escalate confirmed or unclear security events with enough evidence for the next responder.
- Support incident tracking from initial alert through containment, follow-up, and closure notes.
- Assist with vulnerability, patch, and exposure follow-up when assigned by the team.
- Monitor recurring patterns and flag repeated events that may need rule tuning or remediation.
- Document investigation steps without overstating impact or making unsupported claims.
- Prepare concise handoff notes for senior analysts, engineers, or customer-facing teams.
- Support phishing review, suspicious email analysis, and basic user-awareness follow-up.
- Use ticketing and case records consistently so work can be audited and continued.
- Follow AGNIR security handling practices for confidentiality, evidence, and access control.
- Participate in shift handoff, status updates, and remote team coordination.
- Continue learning common frameworks, attack techniques, logs, SIEM concepts, and response basics.
- Protect sensitive operational data and avoid moving evidence outside approved systems.
Basic qualifications
- Associate degree, three-year degree, bachelor's degree, or equivalent cybersecurity/IT qualification.
- Cybersecurity fundamentals, including phishing, malware, identity, endpoint, and network basics.
- Basic networking knowledge, including IP, DNS, ports, protocols, VPN, and firewall concepts.
- Familiarity with Windows, Linux, cloud consoles, logs, SIEM concepts, or EDR tools.
- Ability to write clear investigation notes and communicate remotely with discipline.
- Comfort following escalation procedures and asking for review when evidence is incomplete.
- High attention to detail, time stamps, indicators, user context, and data sensitivity.
- Interest in growing into security operations, incident response, and managed detection work.