IBM-logo
IBM
ยท
September 7, 2026
Apply Now
This job has closed.

Security Operations Center Analyst

Austin, TX
Full-time
Hybrid
$79K/yr - $147K/yr
Entry Level
IBM is a technology and consulting company whose Office of the CISO protects its systems, data, and global operations from cybersecurity threats. The Security Operations Center Analyst serves as a first responder by monitoring and investigating security alerts, analyzing malicious activity, executing containment actions, escalating incidents, and supporting incident response and process improvement.
Apply Now

Responsibilities

  • Monitor and investigate security alerts generated from SIEM, EDR, email security, cloud security, and network security platforms
  • Perform triage and analysis of security events to determine legitimacy, severity, scope, and impact
  • Execute approved containment actions, including host isolation, account restrictions, malicious email remediation, and blocking indicators of compromise
  • Escalate confirmed or high-risk incidents while providing complete investigative context and supporting evidence
  • Analyze endpoint, network, identity, cloud, and application telemetry to identify malicious activity
  • Correlate data from multiple security technologies to investigate complex security events
  • Document investigations, containment actions, and recommendations in accordance with operational procedures
  • Participate in incident response activities and support post-incident reviews as needed
  • Continuously improve detection and triage processes through operational feedback and collaboration with engineering teams
  • Maintain awareness of emerging threats, attacker tactics, techniques, and procedures (TTPs), and industry trends
  • Contribute to operational readiness by assisting with playbook development, process improvement, and knowledge sharing

Qualification

Required

  • Associate's Degree/College Diploma
  • Experience in a Security Operations Center (SOC), Cybersecurity Operations, Incident Response, or related cybersecurity role
  • Experience investigating and triaging security alerts in a large enterprise environment
  • Experience using EDR platforms
  • Experience working with SIEM platforms and log analysis technologies
  • Understanding of common cyber threats, attacker methodologies, and MITRE ATT&CK techniques
  • Experience performing threat containment actions and supporting incident response activities
  • Strong analytical and problem-solving skills with attention to detail
  • Experience analyzing endpoint, identity, email, network, and cloud-based security events
  • Knowledge of Windows, Linux, macOS, Active Directory, Entra ID, and enterprise authentication technologies
  • Working knowledge of networking fundamentals including DNS, TCP/IP, HTTP/S, firewalls, proxies, VPNs, and IDS/IPS technologies
  • Ability to assess risk and prioritize multiple investigations simultaneously in a fast-paced operational environment
  • Strong verbal communication, technical writing, and incident documentation skills
  • Ability to work independently while collaborating effectively across global teams
  • Security Alert Triage and Investigation
  • Event Correlation and Threat Analysis
  • Endpoint Detection and Response (EDR)
  • Security Information and Event Management (SIEM)
  • Account Compromise Investigation
  • Phishing and Business Email Compromise Analysis
  • Threat Containment and Remediation
  • Log Analysis and Query Development
  • Threat Intelligence Utilization
  • Incident Documentation and Case Management

Preferred

  • Bachelor's Degree
  • Experience working within an enterprise SOC supporting global operations
  • Experience using QRadar, Splunk, Sentinel, Elastic, or similar SIEM platforms
  • Experience with CrowdStrike Falcon and/or Microsoft Defender XDR
  • Familiarity with cloud security monitoring in AWS, Azure, IBM Cloud, or GCP environments
  • Experience performing threat hunting activities
  • Knowledge of identity-based attacks and Entra ID / Active Directory investigations
  • Understanding of malware behavior and attacker TTPs
  • Experience developing detections, use cases, or automation workflows
  • Basic scripting skills using Python, PowerShell, KQL, or similar technologies
  • Experience supporting incident response engagements or working closely with a CSIRT organization
  • Cybersecurity certifications such as Security+, CySA+, GCIH, GCIA, GCED, SC-200, SC-300, or equivalent experience

Benefits

  • Healthcare benefits including medical & prescription drug coverage, dental, vision, and mental health & well being
  • 401(k)
  • Cash balance pension plan
  • IBM Employee Stock Purchase Plan
  • Financial counseling
  • Life insurance
  • Short- and long-term disability coverage
  • Opportunities for performance based salary incentive programs
  • 12 paid holidays
  • Minimum 56 hours sick time
  • 120 hours vacation
  • 12 weeks parental bonding leave in accordance with IBM Policy
  • Other Paid Care Leave programs
  • Paid family leave benefits to eligible employees where required by applicable law
  • Training and educational resources on IBM's personalized, AI-driven learning platform
  • Industry-recognized certifications to achieve career goals
  • Diverse and inclusive employee resource groups
  • Giving and volunteer opportunities
  • Discounts on retail products, services & experiences
  • Hybrid work arrangement
IBM provides technology and consulting, including software, infrastructure systems, and cloud-based solutions.
Glassdoor
3.9
Founded in 1911
Armonk, New York, USA
10001+ employees
http://www.ibm.com
IBM provides technology and consulting, including software, infrastructure systems, and cloud-based solutions.
Glassdoor
3.9
Founded in 1911
Armonk, New York, USA
10001+ employees
http://www.ibm.com