{"id":1990469,"url":"https://alion.io/job/evocs-security-analyst","title":"Security Analyst","company":{"id":3907424,"name":"Evocs","domain":"evocs.tech","url":"https://alion.io/company/evocs","size_band":"201-500","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":null},"role":"Security","role_family":"Security","seniority":null,"employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":124800,"max":124800,"currency":"USD","period":"year","gross":null,"usd_annual":124800},"salary_estimate":null,"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Agile","optional":false},{"name":"DNS","optional":false},{"name":"ITSM","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"PagerDuty","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"ServiceNow","optional":false},{"name":"SIEM","optional":false}],"status":"live","first_seen_at":"2026-10-07T05:48:29Z","employer_posted_date":null,"last_verified_at":"2026-10-07T05:48:29Z","board_verified":false,"closed_at":null,"days_open":3,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":3},"description":"This a Full Remote job, the offer is available from: United States\nEVOCS OVERVIEW\nEVOCS was founded with a clear purpose: to help businesses operate more effectively, solve complex challenges, and create opportunities for growth through practical expertise and technology solutions.\nAs an IT consulting firm, we work with our clients to understand their needs, identify the right technologies, and deliver solutions that improve performance and support their business objectives.\nToday, EVOCS is a trusted technology partner to a growing number of organizations and industry leaders. Our team combines technical expertise, business understanding, and a commitment to quality to deliver effective solutions and build lasting client relationships based on responsiveness, consistency, and results.\nSecurity Analyst\nCybersecurity / Security Operations | Remote\nEVOCS Overview\nEVOCS's journey began with a mission to empower businesses with advisory expertise, empowered with ideal technologies to provide them with comprehensive solutions to grow and prosper.\nFounded by a team of passionate experts, EVOCS has grown into a trusted partner to a growing number of leaders across their respective industries. Our roots in employee-managed operations reflect our commitment to quality, consistency, and client success.\nIf you enjoy working in a hyper-fast-growing company, are eager to be part of an agile team, and want to be part of our success story, then let's talk!\nRole Overview\nAs a Security Analyst in the EVOCS Security Operations Centre, you watch a client environment that is genuinely monitored rather than nominally monitored, and you decide what is real. Alerts arrive from endpoint, identity, network, cloud, email, and web application telemetry. You validate them, enrich them until they can be acted on, classify the severity, contain what you are authorized to contain, and escalate the rest with the work already done.\nThe measure of this job is not how many alerts you close. It is whether the person who receives your escalation can act on it without going back to the console to ask a question.\nYou cover the Americas business day within a 24x7 service held across three regions, reporting to the SOC Manager through the senior analyst and shift lead on duty.\nWhat You Will Do\nMonitoring and Triage\nMonitor and triage alerts across a defined client scope, covering the Americas business day within a 24x7 service held across three regions\nValidate whether an alert represents real activity, and close what does not with a recorded reason\nClassify severity against a written scale and record the rationale for the classification, not just the outcome\nEnrichment and Escalation\nEnrich every escalation with asset identity and criticality, the named system owner, exposure context, the identity and its recent behavior, and the blast radius\nEscalate anything outside the pre-approved action schedule to a named approver, and keep the case moving while you wait\nContainment\nExecute containment actions that sit inside the client's pre-approved action schedule - host isolation, session revocation, message purge, block-list changes - and log every one\nCase Management and Handover\nRaise and maintain cases in the client's ITSM platform, and page through the client's on-call tooling; there is no separate EVOCS console holding a second copy of the record\nHand over in writing at shift change, and do not stand down until the incoming lead has acknowledged it\nImprovement and Practice\nFeed false positives and noisy rules back to the detection engineer with enough detail to tune against\nTake part in threat hunts and tabletop exercises as they come round on the rotation\nWhat a Complete Escalation Looks Like\nThis is the standard the role is measured against, so it is worth stating plainly. An escalation is complete when it carries:\nWhat happened, in one sentence a non-analyst can follow\nThe affected asset, its criticality and its named owner\nThe identity involved and what else it did in the detection window\nThe blast radius - every other asset, identity or session the confirmed indicator touched\nExposure context from the vulnerability platform\nThe severity, and why that severity and not the one above or below it\nThe recommended action, and whether you have already taken it\nAn escalation missing any of these sends the recipient back to the console. That is the failure mode this role exists to remove.\nWhat You Will Work With\nSIEM and SOAR - the client's platform of record; you work inside their tenancy\nEndpoint - EDR consoles and response APIs\nIdentity - Entra ID or equivalent, including sign-in, audit and risk detections\nNetwork - next-generation firewall logs, DNS filtering, flow data\nCloud and email - control plane, workload and M365 audit telemetry\nVulnerability - Tenable or equivalent, for exposure context at triage\nWorkflow - ServiceNow for cases, PagerDuty for paging\nFramework - MITRE ATT&CK, and ATT&CK for ICS where operational technology is in scope\nWorking Pattern and Conditions\nHybrid role based on the EVOCS floor; client work is done from the floor on client-provided virtual desktops\nRotating shifts across the Americas business day, with weekend rotation, and no permanent night shift\nThe second Americas site covers Phoenix during a declared continuity event, and Phoenix covers it in turn\nPaid at an hourly rate with overtime at time and a half beyond 40 hours in a workweek, plus a shift differential for evening and weekend rotation\nPersonal phones and removable media are not permitted at consoles\nEmployment is at will\nWhat You Will Bring\nThe top candidate will have the following qualifications:\n2 to 4 years in a SOC, MSSP, incident response team or equivalent monitoring role, with real console time rather than adjacent project work\nHands-on triage across at least three of: endpoint, identity, network, cloud, email\nWorking knowledge of a SIEM and the ability to write and refine your own queries - not only to run somebody else's saved searches\nPractical grasp of how attacks actually proceed: phishing to credential compromise, credential to lateral movement, privilege escalation, persistence, exfiltration\nFamiliarity with MITRE ATT&CK as a working tool, not as a certification topic\nWritten English clear enough that an escalation needs no translation before a client executive reads it\nWillingness to work a rotating shift pattern across the Americas business day, including weekend rotation\nA disposition to write down what you did, including when it was wrong\nKey Skills & Competencies\nAlert triage and validation\nEscalation enrichment and severity classification\nSIEM query writing and refinement\nEndpoint, identity, network, cloud and email telemetry\nContainment execution within an approved action schedule\nWritten handover and case documentation\nIdeally you have…\nScripting for enrichment or automation - Python, PowerShell, KQL, SPL\nExposure to SOAR playbook maintenance\nA cloud or security certification: SC-200, Security+, CySA+, GCIA, GCIH, or a vendor SIEM credential\nAny exposure to operational technology, ICS protocols, or IEC 62443 and NIST SP 800-82\nExperience working to a contracted service level rather than best effort\nPay Range for jobs in the US.\nPay Range$50-$65 USDOur Values\nWe are privileged to serve our loyal customer base in our mission to build lasting relationships with our clients based on trust and mutual success. We strive to deliver exceptional quality and consistency through a white-glove approach. By empowering businesses with tailored solutions and insights, we help them achieve their goals and navigate the ever-evolving tech landscape.\nThe values we live by:\nCustomer-centric Solutions\nInnovation & Excellence\nIntegrity & Transparency\nData-driven Decision Making\nNeed to Know\nThe posting will be active for a minimum of 3 days. The active posting will continue to extend by 3 days until the position is filled.\nAll qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.","description_format":"text","description_chars":8208,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[{"language":"English","level":"All levels","optional":false}]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":[],"lifecycle":[{"event":"open","at":"2026-10-07T05:48:29Z"}],"visa":[],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":2,"expected_fill_days":21,"reasons":["seen:2","velocity","win:early"],"computed_at":"2026-10-10T05:45:15Z"},"pay":{"stated_usd_annual":124800,"is_top_pay":false},"html_url":"https://alion.io/job/evocs-security-analyst","json_url":"https://alion.io/job/evocs-security-analyst.json","meta":{"generated_at":"2026-10-11T01:05:21Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1476,"day_limit":5000,"remaining_today":3524,"minute_limit":60,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":3907424},"rest":"https://alion.io/mcp/rest/get_company?id=3907424"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fevocs-security-analyst"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fevocs-security-analyst"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fevocs-security-analyst"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/evocs-security-analyst\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fevocs-security-analyst"}]}