About the job
The Information Security Analyst (SOC) will play a critical role in our Cloud Security Operations practice by proactively monitoring, detecting, and responding to threats across customer cloud environments. This role focuses on real-time event analysis, cloud-native security visibility, threat intelligence application, and incident response execution. The SOC Analyst will ensure customers’ cloud applications and infrastructure are resilient, compliant, and defended against ever-evolving cyber threats.
What You’ll Do
- Monitor security alerts and events across SIEM, EDR, and cloud services (Google Cloud, AWS).
- Use cloud-native and third-party tools such as Google SecOps, Google Security Command Center, AWS Security Hub, GuardDuty, and others.
- Correlate logs and telemetry from workloads, networks, identities, and apps.
- Fine-tune detection rules and enrichment to reduce false positives and improve threat visibility.
- Perform alert triage.
- Assist in investigations involving access abuse, malware, and cloud misconfigurations.
- Support digital forensics and root cause analysis activities.
- Contribute to the development and automation of incident response playbooks.
- Ensure logging and monitoring coverage for critical assets, identities, and APIs.
- Validate configuration hardening and security controls aligned to cloud best practices.
- Support deployment of SOAR workflows and operational automation.
- Perform proactive threat hunting based on new IOCs and TTPs.
- Help evaluate cloud environments against compliance standards.
- Maintain accurate incident tracking, operational documentation, and customer reporting.
- Provide recommendations to reduce cloud attack surface and strengthen identity access posture.
- Work closely with internal SMEs and customer InfoSec and DevOps teams.
- Communicate findings and response actions clearly to both technical and business stakeholders.
What We’re Looking For
- 1-2 years experience in cybersecurity operations (SOC, CSIRT, threat monitoring, or similar)
- Basic familiarity with at least one major cloud provider (GCP, AWS, or Azure)
- Understanding of network protocols, security logs, and attack methodologies
- Strong analytical and problem-solving skills with attention to detail
- Excellent communication and incident documentation abilities
- Ability to work shifts is essential - 24/7 SOC coverage