1,343,543open jobs
78,629companies
206,623added this week
Browse all
Salary
≈ $60k – $129k per year (Estimated)
Location
In office (Overland Park)
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 7, 2026. First seen by Alion on Aug 28, 2026.

Overview
Company
Impact
Profile match
Stay in command with Foresite’s Agentic SOC. We unify human intuition and agentic scale to neutralize threats at machine speed. Google SecOps-native MDR.

Foresite is seeking a SOC Analyst I who has a passion for security, a keen eye for detail, and a drive to protect organizations from cyberattacks. It's more than just a job; it's a launching pad for your cybersecurity career and a first step towards an exciting future at Foresite.

What You'll Do:

The SOC Analyst I is the entry point to a structured career in Foresite’s Security Operations Center. You will work a dedicated shift inside our 24/7 Cyber Fusion Center, monitoring and triaging security alerts for our managed customers across Google Security Operations (Chronicle), our SOAR platform, and supporting tools. You will learn our detection stack, our customer environments, and our investigation process from experienced analysts and team leads, and you will be measured on clear, published performance criteria that define what it takes to advance to SOC Analyst II.

  • Monitor and triage alerts across Google Security Operations (Chronicle) and the Foresite ticketing queue for assigned customer environments during your shift.
  • Investigate Tier 1 incidents end-to-end: review alert context, gather evidence from Chronicle UDM and supporting tools, reach an initial disposition, and either close the ticket with a documented rationale or escalate as needed with a clear handoff.
  • Follow establishedinvestigation playbooks for the top alert types and rule categories in our detection stack, and flag gaps or outdated guidance to your Team Lead for improvement.
  • Communicate clearly in tickets. Every ticket you touch should be understandable by the next analyst, the customer, or an auditor reading it six months from now. Your written analysis is the primary artifact of your work.
  • Partner with customers through the ticketing system on routine investigations, requests for information, and exclusion/suppression requests under Team Lead oversight.
  • Meet SLA and quality targets for first-touch time, triage accuracy, and ticket closure quality as defined in the L1 performance scorecard.
  • Participate in shift handoff - brief the incoming analyst on open investigations, anomalies observed during your shift, and anything waiting on customer response.
  • Contribute to detections fidelity by flagging noisy rules, false-positive patterns, and alert clusters that should be reviewed by the detection engineering team.

Who you are:

  • Experience: 0-2 years of prior experience in a SOC, IT security, IT operations, or helpdesk/NOC role. Recent graduates of a cybersecurity degree or certificate program are encouraged to apply.

· Working knowledge of core security concepts: the cyber kill chain or MITRE ATT&CK framework, common attack vectors (phishing, credential abuse, malware delivery, lateral movement), and the difference between detection, prevention, and response.

· Familiarity with a SIEM: You do not need Chronicle experience on day one - we will train you - but you must be able to explain what a SIEM does, how alerts are generated, and how to pivot from an alert to supporting log evidence.

· Strong written communication: You will be writing in tickets that customers read. Clear, concise, accurate writing is non-negotiable.

· Attention to detail: False positives and true positives often look nearly identical. The analysts who advance on this team are the ones who read the full log line, not the summary.

· Ability to work an assigned shift on-site in Overland Park: including weekend and holiday coverage as scheduled.

· Security+ certification (or equivalent) within 90 days of hire if not already held.

Nice to Have

  • Hands-on experience with Google Security Operations (Chronicle), Splunk, Elastic, or Microsoft Sentinel
  • BS of IT Security or Cyber Security or currently enrolled in a degree path
  • Familiarity with endpoint detection and response tools (CrowdStrike, SentinelOne, Defender for Endpoint, Carbon Black)
  • Basic scripting or query experience (Python, PowerShell, SQL, or SIEM query languages)
  • Prior MSSP or multi-tenant environment experience
  • Additional certifications: Blue Team Level 1 (BTL1), CompTIA CySA+, GCIA, or Google Cloud Security Engineer

Why Join Foresite?

We are a mission-driven partner helping organizations navigate an increasingly complex threat landscape. Founded by security practitioners, we’ve grown into a global leader in SecOps and MDR by staying true to our core value: radical transparency. When you join Foresite, you are part of a "humans-first" culture where your expertise is valued, and your well-being is a priority. We leverage our Google Cloud Premier SecOps Partnership to stay at the cutting edge, but we know that our greatest asset is our people.

What We Offer

  • Comprehensive Health & Wellness: Robust medical insurance options to keep you and your family healthy.

  • Employer-Covered Insurance: We fully provide employer-paid Dental coverage, as well as Short-Term (STD) and Long-Term Disability (LTD).

  • Recharge & Refuel: We believe in a true work-life balance. You’ll start with 3 weeks of paid vacation, plus additional sick leave and paid company holidays to ensure you have time to recharge.

  • Growth & Mentorship: Access to world-class training and mentorship. We support your career trajectory, whether you’re looking to deepen your technical skills or move into leadership.

  • Impactful Work: Help protect global clients using the latest AI-enhanced security tools and GCP native technologies.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,343,543 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Overland Park
$36k per year • In office • Internship • Beverly Hills
Python
TypeScript
AI/ML
Cursor
Claude
ChatGPT
AI Agents
Mobile
RevenueCat
DevOps
GCP
Cloudflare
SLI/SLO/SLA
GitHub
Cybersecurity
Okta
SOC 2
Least Privilege
Management
Slack
Google Workspace
Apply
≈ $114k – $224k per year (Estimated) • In office • Full-Time • 4+ years exp • San Leandro
Python
DevOps
Terraform
CI/CD
AWS
IAM
Windows
Cybersecurity
Okta
ISO 27001
SOC 2
Least Privilege
SIEM
Apply
≈ $68k – $147k per year (Estimated) • In office • 2+ years exp • Bachelor's Degree • Wichita
AI/ML
Anomaly Detection
Apply
≈ $73k – $145k per year (Estimated) • Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Boca Raton • Seattle
DevOps
Azure
CI/CD
AWS
Platform Engineering
GitHub
Cybersecurity
Qualys Cloud Platform
NIST CSF
CIS Benchmarks
OWASP Top 10
Syft
Dependabot
Clair
OWASP
Apply
≈ $67k – $146k per year (Estimated) • Equity • In office • 1+ year exp • Austin
Python
Go
JavaScript
PowerShell
DevOps
Splunk
Cybersecurity
Cortex XSOAR
Tines
SIEM
Management
Telegram
WhatsApp
Apply
Hybrid
DevOps
SLI/SLO/SLA
Management
Confluence
Jira
Apply
In office • Contractor
PHP
Perl
Databases
MySQL
PostgreSQL
Redis
DevOps
VMWare
Nginx
SLI/SLO/SLA
Linux
Windows
Unix
Apache HTTP Server
Apply
≈ $98k – $183k per year (Estimated) • In office • Full-Time • Bachelor's Degree • United States
DevOps
Terraform
GCP
Azure
CI/CD
AWS
Incident Management
Error Budget
SLI/SLO/SLA
Linux
Cybersecurity
ISO 27001
PCI DSS
SOC 2
Least Privilege
Apply
≈ $55k – $128k per year (Estimated) • In office • Full-Time • Mexico City
AI/ML
NLP
LLM
Cybersecurity
Darktrace
SIEM
Apply
$160k – $180k per year • In office • 12+ years exp • Bachelor's Degree • Twinsburg
DevOps
VMWare
Azure
AWS
SLI/SLO/SLA
Management
ITIL
Service Desk
Apply
≈ $86k – $166k per year (Estimated) • Remote (United States) • Full-Time • 3+ years exp • Overland Park
Python
DevOps
GCP
Git
GitHub
Cybersecurity
Google SecOps
Apply
$74k – $83k per year • Remote (United States) • Public Trust • 10+ years exp • Bachelor's Degree • Overland Park
Python
PowerShell
DevOps
Terraform
Ansible
Azure DevOps
GitHub Actions
Azure
CI/CD
Jenkins
Git
Configuration Management
JFrog Artifactory
GitHub
GitLab
Management
Trello
Confluence
Microsoft Teams
ITIL
Apply
$78k – $104k per year • Remote (United States) • Public Trust • 10+ years exp • Master's Degree • Overland Park
Management
Agile
Scrum
Apply
$12k per year • In office • Part-Time • 2+ years exp • Overland Park
Apply
≈ $82k – $154k per year (Estimated) • In office • Full-Time • 7+ years exp • Bachelor's Degree • Overland Park
Apply
≈ $62k – $116k per year (Estimated) • In office • 4+ years exp • Associate's Degree • Overland Park
Design
AutoCAD
Apply
See all jobs
This is one of many
1,343,543 more open roles from verified company boards, updated every day.