Security Operations Center (SOC) Analyst - Remote

OSIbeyond•Rockville, MD
•Remote

About The Position

OSIbeyond is seeking a Security Operations Center (SOC) Analyst to join their team. This role is a key part of the OSIbeyond ONE platform, focusing on the "People Powered" aspect of security operations. The SOC Analyst will be responsible for monitoring, analyzing, and responding to cybersecurity threats across client environments. This includes validating and investigating alerts, leading incident response, advising clients, and contributing to the continuous improvement of detection and automation logic. The position requires a technically accomplished security professional with strong analytical judgment, disciplined documentation, and professionalism in client communication. The SOC operates on a two-shift, automation-augmented coverage model, with human analysts covering Day and Evening shifts, and an automation layer operating overnight backed by an on-call analyst.

Requirements

  • Two or more years of experience in security operations, incident response, or systems administration with a demonstrable security focus.
  • Demonstrated experience investigating and responding to identity, endpoint, and email-based threats in Microsoft 365 environments.
  • Working knowledge of SIEM operations, log analysis, and alert triage methodology.
  • Understanding of common attack techniques and the MITRE ATT&CK framework, and the ability to map observed activity to adversary behavior.
  • Familiarity with endpoint detection and response, identity protection, and email security controls and their remediation actions.
  • Ability to perform disciplined, well-documented investigations.
  • Solid understanding of Microsoft 365 and Entra ID administration, including conditional access, authentication methods, and audit logging.
  • Working knowledge of Windows server and workstation operating systems, Active Directory, and core networking concepts (TCP/IP, DNS, firewalls, VPN).
  • Familiarity with vulnerability scanning platforms and remediation workflows.
  • Comfort operating within an automation-first environment, including validating and troubleshooting the output of automated playbooks (Tines or comparable SOAR tooling).
  • Basic scripting or query proficiency (PowerShell, KQL, or similar) sufficient to enrich investigations and validate data.
  • Disciplined ticket hygiene and documentation habits; ability to write clear, professional client-facing communications.
  • Reliability and self-management appropriate to a remote, shift-based role with defined coverage responsibilities.
  • CompTIA Security+ certification (or attainment within the first six months).
  • CompTIA Network+ certification (or attainment within the first six months).

Nice To Haves

  • Managed service provider experience is strongly preferred.
  • Experience supporting clients subject to CMMC, NIST SP 800-171, or similar regulatory frameworks.
  • Prior experience contributing to detection engineering or automation playbook development.
  • Experience in a 24x7 or shift-based security operations environment.
  • CompTIA SecurityX (CASP+) or other DoD 8140 Level II certification.

Responsibilities

  • Monitor client environments continuously for security threats using SIEM, endpoint detection and response, identity protection, and email security platforms.
  • Triage inbound alerts, determine if detections represent true positives, benign activity, or tuning opportunities.
  • Respond to alerts where automation is unable to clearly determine legitimacy and/or severity, working and completing assigned tickets in accordance with documented standard operating procedures and service level commitments.
  • Identify recurring false positives and submit detection-tuning recommendations to the SOC Manager and automation team.
  • Investigate security incidents including account compromise, business email compromise, social engineering, malware, and ransomware activity.
  • Analyze servers, workstations, identities, and other assets suspected of compromise to assess the scope and type of the issue.
  • Contain and remediate confirmed threats using approved automation workflows, scripts, policies, playbooks, and platform controls.
  • Escalate incidents in accordance with the incident response plan when the situation exceeds the analyst’s authority or expertise.
  • Provide accurate, timely, and professionally written incident communications to designated client points of contact and internal stakeholders.
  • Perform regularly scheduled vulnerability scanning across client environments.
  • Support client compliance objectives, including CMMC and NIST SP 800-171 requirements.
  • Contribute to periodic client security reviews with clear, data-supported observations.
  • Review the overnight automation log at the start of the Day shift, confirm low confidence actions were appropriate, and remediate or escalate any exceptions.
  • Respond to overnight escalations from the automation layer when on call, take ownership of the incident, and document all actions taken.
  • Identify repetitive manual investigation and response steps and submit them to the automation team as candidates for new automations or expanded playbooks.
  • Identify repetitive “false positives” for the SOC Manager to address.
  • Test and provide structured feedback on new detections and automation workflows before they are placed into production.
  • Track and document all work in the ticketing system with detail sufficient for a peer to resume the work without additional context.
  • Provide high-quality written and verbal customer service in every client interaction.
  • Meet all key performance indicators and notify the SOC Manager promptly when workload or circumstances place a KPI at risk.
  • Recognize when an assignment should be escalated and escalate without delay.
  • Support peers across both shifts and contribute to a collaborative, accountable team culture.
  • Complete training for and maintain awareness of cybersecurity risks, including insider threat, and the appropriate handling of CUI and other regulated data.
  • Treat client data and OSIbeyond data as sensitive, and do not disclose, release, or otherwise transfer it outside of OSIbeyond or client environments without written permission.
  • Follow cybersecurity requirements as described in the Employee Handbook and other OSIbeyond policies.
  • Immediately follow incident response procedures when a security incident or concern is identified.
  • Assist with the escorting or monitoring of visitors when working onsite.
  • Monitor alerts from the SIEM and related security platforms, conduct vulnerability scans, and review and update logged events.

Benefits

  • Medical Insurance - OSIbeyond pays 75% of the premium for the Employee's base medical plan
  • Vision and Dental Insurance - OSIbeyond pays 75% of the premium for the Employee's plans
  • Life Insurance - OSIbeyond pays 100% of the premium for the Employee's plans
  • Short Term Disability Insurance - OSIbeyond pays 100% of the premium for the Employee's plans
  • 401K - OSIbeyond matches up to 4%
  • PTO/Holidays - 9 paid Holidays and accrual based PTO which increases with tenure, new hires start out with 2 weeks.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service