SOC Analyst Jobs
SOC Analyst jobs are open across financial services, healthcare, government, defense, and managed security services, from entry-level tier-one analyst to senior and lead, with specializations in threat detection, incident response, and SIEM engineering. Find a role that fits from the openings below and apply directly.
Find SOC Analyst JobsLooking for remote work? View remote SOC analyst jobs →Student or new grad? View SOC analyst internships →Overview
Showing 5 of 993+ SOC Analyst jobs







Overview
We are seeking an experienced Senior Security Engineer to join our Digital Forensics and Incident Response (DFIR) team within the broader Security Operations Center (SOC), to help our organization respond to cyber-attacks. The ideal candidate will have a deep understanding of the security incident response and incident management process, attacker kill chains / methodologies, be able to respond quickly to attacks, restore services, and forensically investigate the root cause. They will also help defend against emerging AI and agentic system risks, tune detections, and build out threat hunting capabilities. As a member of our SOC, you will closely collaborate with other engineers to design and implement solutions, improve incident response readiness, and provide guidance and training to external teams.
Responsibilities
Oversee and promptly respond to escalated security events or investigations, and activate the Security Incident Response Plan as required.
Provide on-call support for critical severity issues, manage communications, and report incident status to the appropriate stakeholders.
Lead forensic analysis and conduct investigations to ascertain the root cause, scope, and impact of security incidents.
Investigate and respond to incidents involving AI/LLM-based tools and agentic platforms, such as data leakage, insecure output handling, and unauthorized model access, and extend IR playbooks to cover generative AI and AI SOC platform risks.
Develop, maintain, and improve incident response plans, procedures, and playbooks to ensure swift action and regulatory compliance.
Leverage AI SOC platforms and frontier AI tools to accelerate triage, detection tuning, investigation, and documentation, and help evaluate new AI capabilities as they are onboarded.
Present guidance and training on security best practices and incident response to organizational partners, while ensuring alignment with business objectives and compliance requirements.
Mentor and train incident responders on incident handling techniques, forensic analysis, and cloud security forensics and best practices.
Collaborate with Compliance, Legal, and Risk teams to integrate incident response operations with business and regulatory needs.
Assess vulnerabilities, propose remediation strategies, and keep up-to-date on current and emerging security trends, threats, and countermeasures.
Qualifications
A Bachelor's degree or higher in Technology, Computer Science, Cybersecurity, or a related field, or equivalent hands-on experience, is preferred.
Possession of industry-recognized professional certifications such as AWS Security Specialty, GCIH, GCFA, GFCE, CISSP, or emerging AI security credentials is advantageous.
3-5 years of experience in a dedicated cybersecurity role, with a strong emphasis on digital forensics and incident response.
1-3 years writing scripts or code (Bash, PowerShell, Python) to automate security work, comfortable using AI coding assistants and AI SOC platforms to build faster, and aware of the risks that come with AI-generated code.
Working knowledge of AI/LLM security risks and mitigations, such as data exfiltration, insecure output handling, model and data supply chain risk, and shadow AI usage, and familiarity with frameworks such as the OWASP Top 10 for LLM Applications, MITRE ATLAS, and NIST AI RMF.
Experience performing analysis and detection engineering using Endpoint Detection and Response or Cloud Security Posture Management tools such as CrowdStrike Falcon, and Wiz.
Proven threat hunting experience, developing and executing hypothesis-driven hunts across endpoint, cloud, and network telemetry to uncover threats that evade existing detections.
Comprehensive understanding of cybersecurity, networking and cloud fundamentals, and frameworks such as OWASP, MITRE ATT&CK, NIST, and CIS.
Experience using and defending Public Cloud services such as AWS, Azure, and GCP (IAM, CI/CD Pipelines, Network Security, DLP).
Deep understanding of Security Information and Event Management (SIEM) solutions such as Splunk, LogScale.
Strong analytical and problem-solving abilities, with a focus on identifying root causes and assessing risk exposure.
Exceptional communication skills, both verbal and written, capable of explaining technical details to non-technical audiences and fostering strong stakeholder relationships.
Self-motivated with the ability to work autonomously, managing tasks effectively and seeking assistance when necessary.
Proficient in working under pressure in a dynamic environment, prioritizing tasks to meet tight deadlines while maintaining procedural discipline.
Profound knowledge of digital forensics technologies and methodologies, as well as expertise in the Security Incident Response Lifecycle according to frameworks like NIST or SANS.
Adaptable and proactive attitude, willing to take on various responsibilities and eager to continuously learn and upgrade skills.
If you have a passion for security and a proven track record in incident response and security operations, we invite you to apply for this role. Join our SOC and help us protect our organization and our customers from cyber-attacks.
Intuit provides a competitive compensation package with a strong pay for performance rewards approach. This position may be eligible for a cash bonus, equity rewards and benefits, in accordance with our applicable plans and programs (see more about our compensation and benefits at Intuit®: Careers | Benefits). Pay offered is based on factors such as job-related knowledge, skills, experience, and work location. To drive ongoing fair pay for employees, Intuit conducts regular comparisons across categories of ethnicity and gender.
SOC Analyst Jobs by Experience Level
Top Cities Hiring SOC Analysts
Explore SOC analyst openings in the cities hiring most right now.
See All 993+ SOC Analyst Jobs
Find roles that match your experience and apply in just a few clicks.
Find SOC Analyst JobsSOC Analyst Job Market
Who's Hiring
- Allied Universal26

- Northrop Grumman17

- Booz Allen Hamilton16

- Amazon13

- Providence9

Top Industries Hiring
- Technology & Software60
- Healthcare & Medical Services13
- Education11
- Consulting & Professional Services10
- Investment & Asset Management8
What Employers Look For
The qualifications that appear most often in SOC analyst jobs.
- One to three years of hands-on experience in a security operations center environment
- Proficiency with at least one SIEM platform such as Splunk, Microsoft Sentinel, or IBM QRadar
- CompTIA Security+ certification or equivalent entry-level security credential
- Bachelor's degree in cybersecurity, information technology, or a related field
- Experience triaging and documenting security alerts and escalating confirmed incidents
- Familiarity with network protocols, log analysis, and endpoint detection and response tools
Tips for Your SOC Analyst Job Search
Tailor your resume to the tier
Entry-level soc analyst postings weigh certifications like Security+ and hands-on lab experience, while senior roles focus on SIEM tuning, playbook authorship, and escalation ownership. Match the language of each posting to the tier you're targeting, not a single generic template.
Lead with tools you've used
Recruiters filter for specific platforms, Splunk, Microsoft Sentinel, CrowdStrike, and QRadar appear constantly in soc analyst job descriptions. Name every tool you've touched in a dedicated skills section so your resume passes both automated screening and a human hiring manager's quick scan.
Filter openings by shift and environment
SOC roles often require 24/7 shift coverage, so many postings specify day, swing, or overnight schedules. Before applying, confirm the shift structure and whether the role is in-house, hybrid, or fully remote, since these factors affect your day-to-day more than the job title does.
Apply early to roles that fit
Migrate Mate lists soc analyst openings from across the United States in one place, so you can find roles that match and apply directly to each listing.
Prepare for a practical technical screen
Most soc analyst interviews include a scenario-based exercise where you walk through a mock alert, identify indicators of compromise, and explain your escalation decision. Practice narrating your thought process out loud using real case types like phishing triage, failed authentication spikes, and lateral movement patterns.
Negotiate based on shift differential and on-call
Overnight and weekend shifts often carry differential pay that isn't reflected in the base salary listed. Before accepting an offer, ask explicitly whether shift differentials apply, how on-call expectations are structured, and whether tool certification reimbursement is included in the total package.
SOC Analyst Jobs: Frequently Asked Questions
Which companies are hiring the most soc analysts?
The companies hiring the most soc analysts right now include Allied Universal, Northrop Grumman, and Booz Allen Hamilton, with the largest share of openings in Virginia, California, and Texas, based on current listings on Migrate Mate as of September 2026. Defense contractors, managed security service providers, and large financial institutions consistently represent a high share of total postings.
How many soc analyst jobs are remote?
About 65% of soc analyst openings are fully remote or hybrid as of September 2026, though availability varies significantly by sub-discipline. Threat intelligence and malware analysis roles tend to have more remote flexibility, while roles tied to classified environments, on-premises SIEM infrastructure, or government contracts are more likely to require an on-site presence.
How do you become a soc analyst?
Start by building foundational knowledge in networking, operating systems, and security concepts through coursework or self-study, then earn an entry-level certification like CompTIA Security+. Build hands-on experience through home labs, capture-the-flag competitions, or internships. Apply to tier-one analyst roles at managed security providers or enterprises where structured training programs are common for new hires.
Can you get a soc analyst job with little or no experience?
Yes, many employers hire soc analysts without prior professional experience if you can demonstrate practical skills through certifications, home lab projects, or documented CTF participation. Tier-one analyst openings at managed security service providers are the most common entry point, and some organizations offer formal apprenticeship or rotation programs specifically designed for candidates transitioning into the security field.
What does the soc analyst interview process look like?
The soc analyst interview process typically starts with a recruiter screen focused on your background and shift availability, followed by a technical interview covering log analysis, common attack types, and SIEM familiarity. Many employers include a practical scenario exercise where you analyze a mock alert and walk through your triage and escalation decision. Final rounds often involve a panel with the SOC lead or security manager.
Where can I find and apply to soc analyst jobs?
You can find and apply to soc analyst jobs on Migrate Mate, which lists current openings from across the United States. Search the listings to find roles that match your experience level, preferred shift, and technical focus, then apply directly to each one that fits.
See All 993+ SOC Analyst Jobs
Find roles that match your experience and apply in just a few clicks.
Find SOC Analyst Jobs