Location: Charlotte, NC 28202 (Onsite)
Job Type: Full-Time, Permanent
Schedule: Monday to Friday, 8:00 AM - 5:00 PM (On-call rotation every 6 weeks)
About the Role
Our Charlotte technology team is hiring a Cyber Security Analyst to support daily Security Operations Center (SOC) monitoring, threat detection, and incident response. In this role, you will analyze security alerts escalated from Tier 1, investigate potential endpoint and network compromises, and manage vulnerability remediation across our enterprise infrastructure.
You will work closely with our infrastructure and network engineering teams to tune SIEM correlation rules, perform root-cause analysis on security incidents, and ensure compliance with framework standards.
Duties & Responsibilities
- Monitor enterprise SIEM dashboards (Splunk / Microsoft Sentinel) to analyze, triage, and investigate escalated security events and potential alerts.
- Conduct initial incident response for phishing attempts, unauthorized access, malware infections, and credential abuse across endpoints and cloud environments (Azure / M365).
- Run weekly vulnerability scans using Qualys or Tenable, prioritize critical CVE exposure, and collaborate with system administrators to verify patch deployment.
- Review firewalls, EDR agents (CrowdStrike / Defender for Endpoint), and email security gateway logs to identify anomalous network traffic or suspicious process executions.
- Write incident post-mortem reports, document indicators of compromise (IOCs), and update internal Security Orchestration, Automation, and Response (SOAR) playbooks.
- Assist in internal access certification reviews, privileged access management (PAM) audits, and third-party vendor security risk assessments.
Candidate Requirements
- 2 to 4 years of hands-on experience in a SOC, threat monitoring, or cybersecurity analyst role.
- Direct working experience with enterprise SIEM platforms (Splunk, Sentinel, or QRadar) and EDR tools (CrowdStrike, Defender, or SentinelOne).
- Solid understanding of network protocols (TCP/IP, DNS, HTTP/S, BGP) and enterprise authentication models (Active Directory, Entra ID, Okta).
- Active industry certification required (CompTIA Security+, CySA+, GIAC GSEC, or Network+).
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or equivalent practical work experience.
- Must hold valid US work authorization without requiring current or future employer sponsorship.
Compensation & Benefits
- $88,000 - $96,000 base salary depending on relevant technical experience.
- Medical, dental, and vision health coverage starting on day one.
- 401(k) plan with a 5% immediate company match.
- 18 days of Paid Time Off (PTO) plus 10 paid national holidays.
- Annual certification reimbursement budget and ongoing technical training support.
- Covered parking pass or monthly public transit stipend for downtown Charlotte.
How to Apply
To apply, submit an updated resume detailing your experience with SIEM platforms, incident response workflows, and current active certifications. Qualified applicants will be contacted by our internal recruiter for a screening prior to a technical interview with our Information Security Lead.
Pay: $88,000.00 - $96,000.00 per year
Benefits:
- 401(k)
- Dental insurance
- Health insurance
- Life insurance
- Vision insurance
Work Location: In person