Job Requirements
Los Angeles, CA
Top Secret/SCI Polygraph not specified
Early Career (2+ yrs experience)
$88,000 - $121,000
Job Description
Apex is looking for a SOC Analyst to monitor, investigate, and respond to security activity across endpoints, identity, cloud services, networks, and mission-support environments. You will spend most of your time working directly with alerts, logs, vulnerabilities, and investigations to determine what happened and what needs to happen next.
Responsibilities
- Monitor and triage security alerts from CrowdStrike, Elastic SIEM, Microsoft Identity, AWS, and Palo Alto.
- Investigate suspicious logins, phishing emails, privilege changes, and unusual network events.
- Escalate incidents based on affected systems, severity, and CUI impact.
- Work with IT, Cybersecurity, and Network teams on security findings involving our systems and infrastructure.
- Document incidents, required resolutions, and potentially affected assets.
- Maintain recurring logging reviews and incident response documentation with the IT team; collect evidence to support vulnerability management and compliance reporting.
Requirements
- Active TS/SCI clearance required at time of hire
- US Citizenship required
- 2 or more years of experience in a SOC, incident response, threat detection, endpoint security, vulnerability management, or another hands-on cybersecurity operations role
- Experience investigating events using EDR, SIEM, identity, cloud, or network telemetry
- Working knowledge of Windows and Linux, authentication, endpoint behavior, networking fundamentals, common attacker techniques, and cloud logging
- Ability to write useful search queries and filters in a SIEM or log-analysis platform and document investigations so another analyst can continue the work
- Understanding of incident triage, scoping, containment, evidence preservation, escalation, vulnerability prioritization, and post-incident remediation
Preferred Qualifications
- Experience with CrowdStrike Falcon, Palo Alto, Tenable, Elastic Security, Microsoft GCC High, Entra ID, AWS security telemetry, or similar tools
- Experience with detection engineering, threat hunting, MITRE ATT&CK, or scripting in Python, PowerShell, or Bash
- Security+, CySA+, GCIH, GCIA, or a comparable security operations certification
-Experience supporting aerospace, defense, national security, ATO, RMF, or other regulated technical environments
Responsibilities
- Monitor and triage security alerts from CrowdStrike, Elastic SIEM, Microsoft Identity, AWS, and Palo Alto.
- Investigate suspicious logins, phishing emails, privilege changes, and unusual network events.
- Escalate incidents based on affected systems, severity, and CUI impact.
- Work with IT, Cybersecurity, and Network teams on security findings involving our systems and infrastructure.
- Document incidents, required resolutions, and potentially affected assets.
- Maintain recurring logging reviews and incident response documentation with the IT team; collect evidence to support vulnerability management and compliance reporting.
Requirements
- Active TS/SCI clearance required at time of hire
- US Citizenship required
- 2 or more years of experience in a SOC, incident response, threat detection, endpoint security, vulnerability management, or another hands-on cybersecurity operations role
- Experience investigating events using EDR, SIEM, identity, cloud, or network telemetry
- Working knowledge of Windows and Linux, authentication, endpoint behavior, networking fundamentals, common attacker techniques, and cloud logging
- Ability to write useful search queries and filters in a SIEM or log-analysis platform and document investigations so another analyst can continue the work
- Understanding of incident triage, scoping, containment, evidence preservation, escalation, vulnerability prioritization, and post-incident remediation
Preferred Qualifications
- Experience with CrowdStrike Falcon, Palo Alto, Tenable, Elastic Security, Microsoft GCC High, Entra ID, AWS security telemetry, or similar tools
- Experience with detection engineering, threat hunting, MITRE ATT&CK, or scripting in Python, PowerShell, or Bash
- Security+, CySA+, GCIH, GCIA, or a comparable security operations certification
-Experience supporting aerospace, defense, national security, ATO, RMF, or other regulated technical environments
group id: 91136884