Job Monitor / Oil & Gas

Security Operations Center (SOC) Analyst

Airswift · United States · Posted 1 hour ago

Company Airswift Location Houston, United States Employment type Full-time Posted 1 hour ago Listed via Airswift
Security Operations Center (SOC) Analyst Duration: 6 months Location: Houston, TX Schedule: Monday - Friday: 7am - 4pm Role Summary The SOC Analyst is responsible for monitoring, investigating, documenting, and coordinating response to cybersecurity events across enterprise environments. This role is designed for an analyst with 3?5 years of hands-on experience in SOC operations, incident response, phishing investigation, threat monitoring, or related cybersecurity operations. The analyst is expected to communicate clearly, collaborate early with senior cybersecurity personnel and cross-functional teams, and exercise sound judgment during complex or time-sensitive investigations. Key Responsibilities: Monitor, triage, validate, and investigate security alerts from SIEM, EDR, email security, identity, network, cloud, and other cybersecurity platforms. Analyse suspicious activity, indicators of compromise, malware alerts, account compromise indicators, unauthorised access attempts, phishing emails, smishing messages, malicious links, and business email compromise attempts. Document investigation findings, actions taken, supporting evidence, recommendations, and response activities in designated ticketing or case management systems. Coordinate with senior cybersecurity personnel, IT, OT, email administrators, endpoint teams, identity teams, business stakeholders, and affected users to support investigation, containment, remediation, and user guidance. Participate in incident response activities, including evidence gathering, timeline development, stakeholder coordination, lessons learned, and post-incident improvement efforts. Review threat intelligence, vulnerability disclosures, and security advisories to identify relevant indicators, attacker techniques, and potential impacts to the organisation. Conduct proactive threat hunting and recommend detection improvements, correlation rules, alert tuning, and workflow enhancements. Support security control validation, cybersecurity awareness activities, phishing simulations, vulnerability prioritisation, operational reporting, and metrics development. Maintain and improve SOC playbooks, standard operating procedures, investigation templates, knowledge articles, and analyst handoff practices. Communicate investigation status, risk, findings, and recommended next steps clearly to technical and non-technical stakeholders. Must-Have Skills: 3-5 years of hands-on experience in SOC operations, incident response, phishing investigation, threat monitoring, or related cybersecurity operations. Strong understanding of SOC workflows, incident response concepts, threat intelligence, vulnerability management, and security monitoring fundamentals. Experience investigating phishing, smishing, business email compromise, malware activity, credential compromise, suspicious user behaviour, and common attacker tactics. Ability to work with SIEM, EDR, email security, identity, network, and cloud security alerts. Strong technical analysis, documentation, prioritisation, problem-solving, and customer service skills. Ability to collaborate effectively with senior analysts, incident responders, IT, OT, infrastructure, identity, email, endpoint, and business teams. Clear communication skills with the ability to explain findings, risks, investigation status, and recommended next steps to technical and non-technical audiences. Commitment to continuous learning, adaptability, and improving SOC processes, detections, and response workflows. Ability to work in a professional office environment and within or alongside an industrial plant environment, with routine use of standard office equipment. Ability to sit and/or stand for a full shift, lift up to 20 lbs. as needed, move throughout office or site locations, and travel to other company work locations if required. TWIC Card (Required). Remote working is not available for this position. Nice-to-Have: Industry certification such as CompTIA Security+, CompTIA CySA+, Microsoft SC-200, Cisco CyberOps Associate, GSEC, GCIH, CEH, or similar cybersecurity certification (Preferred). Experience writing or modifying SIEM queries, EDR detection logic, threat hunting queries, or basic automation scripts. Knowledge of MITRE ATT&CK, Cyber Kill Chain, NIST incident response concepts, or similar threat and response frameworks. Experience supporting cybersecurity awareness programmes, phishing simulations, vulnerability prioritisation, remediation tracking, control validation, reporting, or exposure management activities. Interest in mentoring junior analysts, improving SOC processes, and contributing to a collaborative, team-oriented security operations culture. About Airswift: Airswift is an international workforce solutions provider within the energy, process and infrastructure industries. Airswift serves as a strategic partner to clients, offering a turnkey workforce solution to capture and deliver the top talent needed to complete successful projects by a
Explore more
519 Airswift jobs → 3637 jobs in United States →
Oil & Gas Alert tracks 21+ employer career pages and delivers daily digests of new vacancies. Set your own keywords →