SOC Analyst
Mantis Security is seeking an experienced Security Operations Center (SOC) Analyst to support the monitoring, detection, investigation, and response to cybersecurity threats within a mission-focused environment. This position will work as part of a security operations team responsible for protecting both traditional and AWS cloud-based infrastructure.
The ideal candidate will have a strong foundation in security operations and incident response, with hands-on experience analyzing security events across AWS environments. This role requires someone who can move beyond simply reviewing alerts to determine what happened, assess the potential impact, document findings, and support appropriate response and remediation actions.
As a SOC Analyst at Mantis Security, you'll help protect critical customer environments by monitoring, investigating, and responding to cybersecurity threats across both traditional and AWS cloud infrastructure.
- Monitor and investigate security alerts across enterprise and AWS environments
- Triage potential threats, determine impact, and support incident response and remediation
- Analyze security activity using SIEM, EDR, and AWS security tools including GuardDuty, Security Hub, CloudTrail, and CloudWatch
- Investigate suspicious account activity, credential misuse, network traffic, malware, and other indicators of compromise
- Conduct threat hunting and correlate activity across multiple data sources to identify emerging or previously undetected threats
- Document investigations, communicate findings, and escalate incidents when necessary
- Help improve SOC detection capabilities, playbooks, processes, and alerting
Requirements
WHAT WE'RE LOOKING FOR:
- 7+ years of cybersecurity, SOC, incident response, or related experience
- Hands-on experience investigating security events in AWS environments
- Experience working with SIEM and endpoint detection and response (EDR) platforms
- Working knowledge of AWS IAM, EC2, S3, VPC, CloudTrail, GuardDuty, Security Hub, and related security concepts
- Strong understanding of network security, common attack techniques, and incident response
- Ability to analyze complex technical information and clearly communicate findings
- Familiarity with MITRE ATT&CK, threat intelligence, and vulnerability management
- Security+ or equivalent cybersecurity certification
- Active TS/SCI security clearance required.
NICE TO HAVE:
- Experience supporting DoD, Intelligence Community, or other federal environments
- AWS security or architecture certification
- Experience with Splunk and AWS GovCloud
- Basic Python, PowerShell, or Bash scripting experience