{"id":1945871,"url":"https://alion.io/job/foresite-soc-analyst","title":"SOC Analyst","company":{"id":2375834,"name":"Foresite","domain":"foresite.com","url":"https://alion.io/company/foresite-com","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Schema","truth_index":null},"role":"Security","role_family":"Security","seniority":"junior","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Overland Park, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":60000,"max_usd":129000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":224},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Cyber Kill Chain","optional":false},{"name":"SIEM","optional":false},{"name":"SLI/SLO/SLA","optional":false},{"name":"Carbon Black","optional":true},{"name":"Crowdstrike","optional":true},{"name":"GCP","optional":true},{"name":"Microsoft Sentinel","optional":true},{"name":"PowerShell","optional":true},{"name":"Python","optional":true},{"name":"SentinelOne","optional":true},{"name":"Splunk","optional":true},{"name":"SQL","optional":true}],"status":"live","first_seen_at":"2026-08-28T13:55:49Z","employer_posted_date":"2026-09-14","last_verified_at":"2026-10-07T18:41:02Z","board_verified":true,"closed_at":null,"days_open":41,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":41},"description":"Foresite is seeking a SOC Analyst I who has a passion for security, a keen eye for detail, and a drive to protect organizations from cyberattacks. It's more than just a job; it's a launching pad for your cybersecurity career and a first step towards an exciting future at Foresite.\nWhat You'll Do:\nThe SOC Analyst I is the entry point to a structured career in Foresite’s Security Operations Center. You will work a dedicated shift inside our 24/7 Cyber Fusion Center, monitoring and triaging security alerts for our managed customers across Google Security Operations (Chronicle), our SOAR platform, and supporting tools. You will learn our detection stack, our customer environments, and our investigation process from experienced analysts and team leads, and you will be measured on clear, published performance criteria that define what it takes to advance to SOC Analyst II.\nMonitor and triage alerts across Google Security Operations (Chronicle) and the Foresite ticketing queue for assigned customer environments during your shift.\nInvestigate Tier 1 incidents end-to-end: review alert context, gather evidence from Chronicle UDM and supporting tools, reach an initial disposition, and either close the ticket with a documented rationale or escalate as needed with a clear handoff.\nFollow establishedinvestigation playbooks for the top alert types and rule categories in our detection stack, and flag gaps or outdated guidance to your Team Lead for improvement.\nCommunicate clearly in tickets. Every ticket you touch should be understandable by the next analyst, the customer, or an auditor reading it six months from now. Your written analysis is the primary artifact of your work.\nPartner with customers through the ticketing system on routine investigations, requests for information, and exclusion/suppression requests under Team Lead oversight.\nMeet SLA and quality targets for first-touch time, triage accuracy, and ticket closure quality as defined in the L1 performance scorecard.\nParticipate in shift handoff - brief the incoming analyst on open investigations, anomalies observed during your shift, and anything waiting on customer response.\nContribute to detections fidelity by flagging noisy rules, false-positive patterns, and alert clusters that should be reviewed by the detection engineering team.\nWho you are:\nExperience: 0-2 years of prior experience in a SOC, IT security, IT operations, or helpdesk/NOC role. Recent graduates of a cybersecurity degree or certificate program are encouraged to apply.\n\n· Working knowledge of core security concepts: the cyber kill chain or MITRE ATT&CK framework, common attack vectors (phishing, credential abuse, malware delivery, lateral movement), and the difference between detection, prevention, and response.\n· Familiarity with a SIEM: You do not need Chronicle experience on day one - we will train you - but you must be able to explain what a SIEM does, how alerts are generated, and how to pivot from an alert to supporting log evidence.\n· Strong written communication: You will be writing in tickets that customers read. Clear, concise, accurate writing is non-negotiable.\n· Attention to detail: False positives and true positives often look nearly identical. The analysts who advance on this team are the ones who read the full log line, not the summary.\n· Ability to work an assigned shift on-site in Overland Park: including weekend and holiday coverage as scheduled.\n· Security+ certification (or equivalent) within 90 days of hire if not already held.\nNice to Have\nHands-on experience with Google Security Operations (Chronicle), Splunk, Elastic, or Microsoft Sentinel\nBS of IT Security or Cyber Security or currently enrolled in a degree path\nFamiliarity with endpoint detection and response tools (CrowdStrike, SentinelOne, Defender for Endpoint, Carbon Black)\nBasic scripting or query experience (Python, PowerShell, SQL, or SIEM query languages)\nPrior MSSP or multi-tenant environment experience\nAdditional certifications: Blue Team Level 1 (BTL1), CompTIA CySA+, GCIA, or Google Cloud Security Engineer\nWhy Join Foresite?\nWe are a mission-driven partner helping organizations navigate an increasingly complex threat landscape. Founded by security practitioners, we’ve grown into a global leader in SecOps and MDR by staying true to our core value: radical transparency. When you join Foresite, you are part of a \"humans-first\" culture where your expertise is valued, and your well-being is a priority. We leverage our Google Cloud Premier SecOps Partnership to stay at the cutting edge, but we know that our greatest asset is our people.\nWhat We Offer\nComprehensive Health & Wellness: Robust medical insurance options to keep you and your family healthy.\n\nEmployer-Covered Insurance: We fully provide employer-paid Dental coverage, as well as Short-Term (STD) and Long-Term Disability (LTD).\n\nRecharge & Refuel: We believe in a true work-life balance. You’ll start with 3 weeks of paid vacation, plus additional sick leave and paid company holidays to ensure you have time to recharge.\n\nGrowth & Mentorship: Access to world-class training and mentorship. We support your career trajectory, whether you’re looking to deepen your technical skills or move into leadership.\n\nImpactful Work: Help protect global clients using the latest AI-enhanced security tools and GCP native technologies.","description_format":"text","description_chars":5367,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["Health insurance"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Incident Response","Cybersecurity","Security Operations"],"lifecycle":[{"event":"open","at":"2026-10-06T06:55:45Z"}],"visa":[],"liveness":{"score":13,"band":"cold","label":"Long shot","p_open":1,"p_active":0.473,"p_room":0.28,"age_days":40,"expected_fill_days":16,"reasons":["conf:11","win:tail","crowd:junior"],"computed_at":"2026-10-08T05:49:30Z"},"pay":null,"html_url":"https://alion.io/job/foresite-soc-analyst","json_url":"https://alion.io/job/foresite-soc-analyst.json","meta":{"generated_at":"2026-10-09T03:11:28Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1600,"day_limit":5000,"remaining_today":3400,"minute_limit":60,"resets_at":"2026-10-10T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":2375834},"rest":"https://alion.io/mcp/rest/get_company?id=2375834"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fforesite-soc-analyst"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fforesite-soc-analyst"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fforesite-soc-analyst"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/foresite-soc-analyst\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fforesite-soc-analyst"}]}