SOC Analyst 1
BlackSwan Cybersecurity // San Antonio, TX
- Assume shift lead responsibilities in a 24/7 embedded SOC supporting national energy, leading off-hours and weekend incident response.
- Update and maintain firewall configurations to meet NERC CIP compliance requirements for critical infrastructure.
- Develop KQL queries in Microsoft Sentinel and use NDR tooling to detect anomalies and investigate threats.
- Perform Tier 2 responsibilities including deeper incident investigation, threat hunting, and escalation support.
- Use threat intelligence enrichment and detection tuning to improve correlation and reduce false positives.
- Classify, prioritize, and escalate alerts based on threat severity in a high-availability, mission-critical setting.
- Assume incident command during off-hours and weekend shifts, coordinating analyst response and ensuring continuity of SOC operations.
- Maintain incident response documentation and post-incident reporting in ServiceNow.