SOC Analyst Tier 1
San Antonio
Saturday, 06 June 2026
Monitor security alerts and events in the Security Operations Center (SOC) and perform initial triage, analysis, and escalation as needed. Investigate potential security incidents using SIEM, endpoint, network, and other security tools to determine scope, impact, and next steps. Document findings, actions taken, and incident details clearly and accurately in accordance with SOC procedures and reporting requirements. Escalate confirmed or high-risk incidents to senior analysts or incident response teams when appropriateSupport threat detection, alert tuning, and ongoing improvement of SOC monitoring processes and playbooks. Collaborate with internal teams to gather information, support investigations, and help protect enterprise systems and data. Stay current on common cyber threats, vulnerabilities, and attacker tactics, techniques, and procedures (TT - Ps). What You Will Need:Requires a Bachelors Degree and minimum 0-2 years of prior relevant experience. Ideally experience in cybersecurity, information technology, or a related technical support role. Basic understanding of security operations, incident response, and common cyber threats. Familiarity with SIEM tools, log analysis, and endpoint or network security concepts. Strong analytical and problem-solving skills with the ability to prioritize and respond to alerts in a fast-paced environment. Excellent written and verbal communication skills with attention to detail and documentation accuracy. Ability to work collaboratively with cross-functional teams and follow established procedures. High school diploma or equivalent required; associate’s or bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field preferred. Must be able to work full time and support SOC operations as needed. US Citizenship is required. Must be able to OBTAIN and MAINTAIN a "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse. Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY are preferred. What Would Be Nice To Have:Experience with tools such as Splunk, Q - Radar, Microsoft Sentinel, or similar SIEM platforms. Security certifications such as Security , Cy. SA , GSEC, or equivalent. Exposure to incident response, threat hunting, vulnerability management, or malware analysis. Basic scripting or automation skills (Python, PowerShell, or similar). Knowledge of frameworks such as MITRE ATT&CK, NIST, or CIS controls.