SOC Analyst
Mantis Security Corporation · Reston, VA
Apply & track with Apply EdgeMantis Security is seeking an experienced Security Operations Center (SOC) Analyst to support the monitoring, detection, investigation, and response to cybersecurity threats within a mission-focused environment. This position will work as part of a security operations team responsible for protecting both traditional and AWS cloud-based infrastructure.The ideal candidate will have a strong foundation in security operations and incident response, with hands-on experience analyzing security events across AWS environments. This role requires someone who can move beyond simply reviewing alerts to determine what happened, assess the potential impact, document findings, and support appropriate response and remediation actions.As a SOC Analyst at Mantis Security, you'll help protect critical customer environments by monitoring, investigating, and responding to cybersecurity threats across both traditional and AWS cloud infrastructure.Monitor and investigate security alerts across enterprise and AWS environmentsTriage potential threats, determine impact, and support incident response and remediationAnalyze security activity using SIEM, EDR, and AWS security tools including GuardDuty, Security Hub, CloudTrail, and CloudWatchInvestigate suspicious account activity, credential misuse, network traffic, malware, and other indicators of compromiseConduct threat hunting and correlate activity across multiple data sources to identify emerging or previously undetected threatsDocument investigations, communicate findings, and escalate incidents when necessaryHelp improve SOC detection capabilities, playbooks, processes, and alertingRequirementsWHAT WE'RE LOOKING FOR:7+ years of cybersecurity, SOC, incident response, or related experienceHands-on experience investigating security events in AWS environmentsExperience working with SIEM and endpoint detection and response (EDR) platformsWorking knowledge of AWS IAM, EC2, S3, VPC, CloudTrail, GuardDuty, Security Hub, and related security conceptsStrong understanding of network security, common attack techniques, and incident responseAbility to analyze complex technical information and clearly communicate findingsFamiliarity with MITRE ATT&CK, threat intelligence, and vulnerability managementSecurity+ or equivalent cybersecurity certificationActive TS/SCI security clearance requiredNICE TO HAVE:Experience supporting DoD, Intelligence Community, or other federal environmentsAWS security or architecture certificationExperience with Splunk and AWS GovCloudBasic Python, PowerShell, or Bash scripting experience