寻找你的下一个职业机会

按职位、技能和地点搜索招聘信息。准备申请前,先仔细了解职位要求。

找到一个吸引人的职位名称只是求职的起点。请将工作职责、招聘要求和工作条件与你的实际经历进行比较。本指南帮助你筛选机会、准备有针对性的申请材料,并确认每份申请应该在哪里提交。

此界面为简体中文。雇主发布的职位名称和描述保留原文,可能为英文。

清除筛选

搜索结果: 8,529

← 返回搜索结果

Security Operations Center (SOC) Analyst – SIEM / Splunk

WFLink

地点
Anywhere
发布日期
2026年10月8日

申请前,请在雇主网站确认职位仍在招聘,并检查完整要求和条件。

职位描述

此界面为简体中文。雇主发布的职位名称和描述保留原文,可能为英文。

Position Title Security Operations Center (SOC) Analyst – SIEM / Splunk Location Remote (U.S.) with Occasional Travel Client Federal / Public Sector Programs Work Authorization Candidates must be authorized to work in the United States. U.S. Citizenship may be required based on client assignment. 📩 To apply, please submit your resume to careers@wintrio.com or complete the application form below. Job Summary WINTrio LLC is seeking a Security Operations Center (SOC) Analyst with experience supporting Security Information and Event Management (SIEM) platforms, particularly Splunk, within Federal cybersecurity environments. This role is responsible for monitoring security events, investigating alerts, supporting incident response activities, conducting threat analysis, and enhancing operational visibility across enterprise systems. The successful candidate will help protect Federal environments by identifying suspicious activity, responding to security incidents, supporting continuous monitoring initiatives, and improving detection capabilities across cloud, network, application, and endpoint environments. The ideal candidate possesses strong analytical skills, experience working in a SOC or cybersecurity operations environment, and the ability to investigate and respond to security events in accordance with Federal cybersecurity requirements. Job Responsibilities Monitor security alerts, events, and indicators using Splunk, SIEM dashboards, endpoint security platforms, network monitoring tools, and cloud security services. Triage, investigate, document, and escalate security incidents based on severity, risk, mission impact, and established procedures. Correlate security events across firewalls, endpoints, identity systems, vulnerability scanners, applications, and cloud platforms. Develop, maintain, and refine Splunk searches, alerts, dashboards, reports, and correlation rules. Support incident response activities, including containment, eradication, recovery, evidence collection, and after-action reporting. Analyze logs from Windows, Linux, Active Directory, Azure AD/Entra ID, cloud services, firewalls, IDS/IPS solutions, endpoint detection platforms, and enterprise applications. Support continuous monitoring, threat hunting, insider threat investigations, and suspicious activity detection efforts. Document incidents, findings, timelines, remediation actions, and lessons learned using ServiceNow, JIRA, or similar tracking systems. Support reporting activities aligned with Federal cybersecurity requirements, SLAs, compliance mandates, and incident response procedures. Assist with SOC process improvement initiatives, playbook development, detection engineering, and workflow automation efforts. Collaborate with cybersecurity, infrastructure, cloud, and application teams to strengthen organizational security posture. Required Qualifications Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field, or equivalent professional experience. Minimum three (3) years of experience supporting cybersecurity operations, SOC activities, incident response, threat monitoring, or SIEM administration. Hands-on experience using Splunk or comparable SIEM platforms. Strong understanding of incident response processes, threat detection methodologies, log analysis, and alert triage. Experience analyzing endpoint, network, identity, application, and cloud security logs. Familiarity with Federal cybersecurity requirements, continuous monitoring programs, and compliance reporting. Strong written and verbal communication skills. Strong analytical, investigative, and problem-solving abilities. Technical Areas Security Operations & Incident Response Security Event Monitoring Alert Triage Incident Investigation Incident Response Threat Detection Threat Hunting Continuous Monitoring Security Reporting SIEM & Log Analysis Log Correlation Security Analytics Detection Engineering Correlation Rule Development Dashboard Development Operational Reporting Threat Intelligence & Analysis MITRE ATT&CK Framework CISA Known Exploited Vulnerabilities (KEV) CVE Analysis Indicators of Compromise (IOC) Threat Intelligence Enrichment Adversary Tactics & Techniques Cloud & Enterprise Security AWS Security Monitoring Azure Security Monitoring Identity Security Monitoring Network Security Monitoring Endpoint Security Monitoring Tools & Platforms SIEM Platforms Splunk Enterprise Splunk Enterprise Security ELK Stack Microsoft Sentinel IBM QRadar Endpoint & EDR Platforms CrowdStrike Microsoft Defender Carbon Black Trellix SentinelOne Network Security Tools Firewalls IDS/IPS Platforms VPN Monitoring NetFlow Analysis Wireshark Identity & Access Security Active Directory Microsoft Entra ID (Azure AD) Privileged Access Monitoring Cloud Security Monitoring AWS CloudTrail Amazon GuardDuty AWS CloudWatch Azure Monitor Microsoft Defender for Cloud Incident Management & Collaboration ServiceNow JIRA SOAR Platforms Case Management Systems Scripting & Automation Python PowerShell Bash Preferred Certifications CompTIA Security+ CompTIA CySA+ Splunk Core Certified User Splunk Core Certified Power User Splunk Enterprise Security Certified Administrator GIAC Certified Incident Handler (GCIH) GIAC Security Essentials (GSEC) Certified Ethical Hacker (CEH) Microsoft Security Operations Analyst Associate Preferred Qualifications Experience supporting Federal SOC, continuous monitoring, or incident response programs. Experience creating Splunk dashboards, alerts, correlation searches, and executive-level reporting. Experience supporting SOAR automation initiatives, threat hunting programs, or detection engineering activities. Experience supporting cloud-hosted or hybrid technology environments. Familiarity with NIST SP 800-53, NIST SP 800-61, FISMA, DHS CDM, and FedRAMP requirements. Experience supporting enterprise cybersecurity operations centers. Work Environment Full-time position. Remote within the United States. Standard business hours Monday through Friday. Occasional travel may be required in support of customer meetings, incident response activities, and program requirements. WINTrio Benefits Healthcare (Medical, Dental, and Vision) Flexible Spending Account (FSA) and Health Savings Account (HSA) 401(k) and Retirement Savings Plan Annual Bonus and Profit Sharing Opportunities Paid Time Off (PTO) and Vacation Employee Assistance Program (EAP) Life, Personal, and Voluntary Disability Insurance Growth Opportunities There is ample opportunity to grow in multiple dimensions, including cybersecurity operations, incident response, threat hunting, cloud security, detection engineering, security automation, cyber defense, and cybersecurity leadership. We are a completely employee-driven company, and our continued success is built on the talent, dedication, and innovation of our team members. Equal Opportunity Employer WINTrio LLC is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, age, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law.

查找职位、比较要求,再准备申请

从你希望从事的职位或运用的技能开始搜索。调整地点和职业筛选,打开职位比较工作职责。如果没有结果,可以使用更短的关键词,或逐一移除筛选条件。

区分必备要求和优先条件,检查已列出的工作安排、薪资和地点。远程职位也可能要求特定居住国家、工作许可或工作时间重合。请向雇主确认职位信息和完整条件。

选择能够回应职位要求的真实经历,说明你的贡献,只使用能够证实的数字。遵循雇主的申请说明,并在提交前检查联系方式、文档内容和 PDF。

提交申请前的检查清单

求职常见问题

为什么有些职位使用英文?

职位名称和描述由招聘企业撰写。为避免改变招聘要求或工作条件,我们保留原文。操作界面和本指南使用简体中文。如果中文搜索没有结果,可以尝试使用职位发布语言中的名称或技能,例如“software engineer”。搜索词不会自动翻译,界面语言也不代表企业要求的申请语言。

远程职位是否允许从任何国家工作?

不一定。企业可能对居住国家、工作许可或工作时段有要求。请查看原始招聘页面中的具体条件。如果未说明,应先向企业确认,再判断能否从你所在的地区工作。“远程”标签本身并不代表没有地点限制。

搜索没有结果时应该怎么办?

尝试更通用的职位名称或单个技能,并逐一移除筛选条件。不同企业可能用不同名称描述相似工作。如果某个职位已经消失,请在企业招聘页面搜索其职位编号。扩大搜索范围不会让已经关闭的职位重新开放。

申请会通过 ResumizeAI 直接提交吗?

申请按钮会打开外部网站。请按照企业或招聘服务的说明,在该网站完成并确认提交。在 ResumizeAI 中准备简历并不等于已经申请职位。如果链接只打开企业网站,请先找到对应职位,再继续申请流程。

如何针对职位调整简历和求职信?

将招聘要求与能够解释清楚的项目、任务和成果联系起来。突出相关经历,不要添加未经实际掌握的技能或虚构成绩。在求职信中用具体例子说明申请动机,并遵守企业要求的语言和文件格式。提交前检查两份文件,确保内容准确、联系方式正确、链接可用。