Security Operations Center (SOC) Analyst

TriCom Technical Services LLC
  • St. Paul, MN
    3 days ago

    Job Description

    Security Operations Center Analyst

    Summary

    TriCom is seeking a Security Operations Center Analyst to support and enhance day-to-day cybersecurity operations. This role will be responsible for monitoring, investigating, and responding to security events across enterprise systems while helping strengthen the organization's overall security posture. The ideal candidate will have hands-on experience with security monitoring, incident response, threat hunting, phishing investigations, and modern security platforms including Microsoft Defender XDR, Sentinel, Entra ID, Intune, and CrowdStrike. This is a hybrid position that may require occasional after-hours support during active security incidents.

    Responsibilities

    • Monitor, investigate, and remediate security alerts across enterprise environments.
    • Perform proactive threat hunting to identify indicators of compromise and potential security risks.
    • Analyze phishing emails and suspicious communications to identify threats and recommend remediation actions.
    • Operate and monitor the organization's security tool stack including Microsoft Defender XDR, Sentinel, Entra ID, Intune, CrowdStrike, and Active Directory auditing solutions.
    • Create, update, escalate, and track security incidents through ServiceNow.
    • Conduct incident documentation, reporting, and after-action reviews.
    • Collaborate with cybersecurity and IT teams to strengthen security controls and improve operational response processes.
    • Stay current on cybersecurity trends, threat intelligence, and evolving attack techniques.

    Requirements

    • Minimum 2+ years of experience in a Security Operations Center (SOC) or related cybersecurity role.

    • Experience performing security alert triage, remediation, incident investigation, and after-action documentation.

    • Working knowledge of threat hunting techniques including IOC analysis, threat intelligence review, anomaly detection, and suspicious IP investigations.

    • Experience analyzing phishing emails including email header analysis and spoofing identification.

    • Hands-on experience with:

    • Microsoft Defender XDR;

    • Microsoft Sentinel;

    • Microsoft Entra ID;

    • Microsoft Intune.

    • Experience supporting CrowdStrike Endpoint protection and Next-Generation SIEM (NGSIEM) platforms.

    • Experience conducting Active Directory security audits and investigations.

    • Experience managing and updating incidents within ServiceNow.

    • Strong analytical, problem-solving, and troubleshooting skills.

    • Excellent written and verbal communication skills.

    • Close attention to detail and ability to work effectively in a collaborative team environment.

    Preferred

    • Experience supporting municipal, government, or highly regulated environments.
    • Familiarity with security frameworks and cybersecurity best practices.
    • Experience with incident response processes and forensic investigations.
    • Security certifications including Security+, CySA+, GSEC, GCIA, SC-200, or similar.
    • Experience with automation, scripting, or security orchestration tools.
    • Knowledge of emerging cyber threats, attack techniques, and industry threat intelligence sources.

    This is a 4-month-plus Contract opportunity with potential for hire with our MN client. Low-cost employee benefits, paid time off, paid Holidays, and a 401(k) (with an immediately vested company match) are available with TriCom during the contract period. H-1B visa sponsorship is not available for this position. No third-parties, please.

    #LI-SK1

    Numbers & Facts

    LocationSt. Paul, MN

    Skills

    • Analysis Skillsunmatched
    • Auditingunmatched
    • Best Practicesunmatched
    • Communication Skillsunmatched
    • CompTIA Security+unmatched
    • Computer Securityunmatched
    • Detail Orientedunmatched
    • Documentationunmatched
    • Endpoint Securityunmatched
    • Enterprise Protectionunmatched
    • GCIA - GIAC Certified Intrusion Analystunmatched
    • GSEC - GIAC Security Essentials Certificationunmatched
    • Governmentunmatched
    • Huntingunmatched
    • IP (Internet Protocol)unmatched
    • Incident Responseunmatched
    • Internet Securityunmatched
    • Inversion of Control (IoC)unmatched
    • Microsoft Active Directoryunmatched
    • Microsoft Product Familyunmatched
    • Operational Auditunmatched
    • Operational Improvementunmatched
    • Operations Processesunmatched
    • Phishingunmatched
    • Presentation/Verbal Skillsunmatched
    • Process Improvementunmatched
    • Scripting (Scripting Languages)unmatched
    • Security Analysisunmatched
    • Security Attacksunmatched
    • Security Auditingunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Security Infrastructureunmatched
    • Security Monitoringunmatched
    • ServiceNowunmatched
    • Team Playerunmatched
    • Writing Skillsunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder