SOC Analyst
Mantis Security is seeking an experienced Security Operations Center (SOC) Analyst to support the monitoring, detection, investigation, and response to cybersecurity threats within a mission-focused environment. This position will work as part of a security operations team responsible for protecting both traditional and AWS cloud-based infrastructure.
The ideal candidate will have a strong foundation in security operations and incident response, with hands-on experience analyzing security events across AWS environments. This role requires someone who can move beyond simply reviewing alerts to determine what happened, assess the potential impact, document findings, and support appropriate response and remediation actions.
As a SOC Analyst at Mantis Security, you'll help protect critical customer environments by monitoring, investigating, and responding to cybersecurity threats across both traditional and AWS cloud infrastructure.
Monitor and investigate security alerts across enterprise and AWS environments
Triage potential threats, determine impact, and support incident response and remediation
Analyze security activity using SIEM, EDR, and AWS security tools including GuardDuty, Security Hub, CloudTrail, and CloudWatch
Investigate suspicious account activity, credential misuse, network traffic, malware, and other indicators of compromise
Conduct threat hunting and correlate activity across multiple data sources to identify emerging or previously undetected threats
Document investigations, communicate findings, and escalate incidents when necessary
Help improve SOC detection capabilities, playbooks, processes, and alerting
Requirements
WHAT WE'RE LOOKING FOR:
7+ years of cybersecurity, SOC, incident response, or related experience
Hands-on experience investigating security events in AWS environments
Experience working with SIEM and endpoint detection and response (EDR) platforms
Working knowledge of AWS IAM, EC2, S3, VPC, CloudTrail, GuardDuty, Security Hub, and related security concepts
Strong understanding of network security, common attack techniques, and incident response
Ability to analyze complex technical information and clearly communicate findings
Familiarity with MITRE ATT&CK, threat intelligence, and vulnerability management
Security+ or equivalent cybersecurity certification
Active TS/SCI security clearance required.
NICE TO HAVE:
Experience supporting DoD, Intelligence Community, or other federal environments
AWS security or architecture certification
Experience with Splunk and AWS GovCloud
Basic Python, PowerShell, or Bash scripting experience
QPciGRaBGo