Tier 1 SOC Analyst
Location: Fully Remote (U.S.) Type: Full-time, hourly Pay: $20 – $25/hour + shift differential for nights and weekends Schedule: Rotating 8-hour shifts, days or nights
Real security work, from day one
Most entry-level SOC jobs are alert factories: close the ticket, move to the next one, learn nothing.
That's not how we run our SOC. At VDA Labs you'll investigate alerts across a portfolio of real client environments — manufacturers, healthcare practices, school districts, casinos, financial firms, using enterprise tooling like Securonix, SentinelOne, Crowdstrike and Huntress. You'll map what you find to MITRE ATT&CK, write the investigation up in your own words, and talk directly to the client about what happened and what to do next.
If you're coming out of a cyber program, a help desk role, or a career change and you want the reps that actually build an analyst, this is the seat.
What you'll do
- Monitor and triage. Work the alert queue across client environments during your shift in our 24x7x365 SOC — validating detections, separating true positives from noise, and pulling the thread when something looks wrong.
- Investigate. Use MITRE ATT&CK and Cyber Kill Chain analysis to understand what an attacker was attempting, how far they got, and what else may have been touched.
- Respond. Follow established playbooks to contain, remediate, or escalate — and know when the playbook doesn't cover what you're seeing.
- Write it down clearly. Deliver investigation reports to clients through our service management system. Clear writing is a core skill here, not a nice-to-have.
- Talk to clients. Stay engaged through the lifecycle of escalated investigations, including calls with client IT and leadership.
- Hand off cleanly. Participate in shift handovers, team huddles, and internal reviews so nothing gets dropped between shifts.
- Keep sharpening. Stay current on emerging vulnerabilities, threat actor tradecraft, and attack trends — on paid time, with training we sponsor.
Your first 90 days
- Days 1–30: Onboarding and tooling. You'll shadow experienced analysts, learn our detection stack and playbooks, and start working alerts with a senior analyst reviewing your calls.
- Days 31–60: You're running your own queue during your shift, writing client-facing reports, and escalating with confidence.
- Days 61–90: You're a full shift contributor — handling escalations independently, joining client calls, and starting to spot detection tuning opportunities.
What we're looking for
You'll need:
- Foundational understanding of networking and endpoint security — how systems talk, what normal looks like, and how attackers abuse both
- Familiarity with MITRE ATT&CK and the Cyber Kill Chain
- Strong written communication — you can explain a technical finding to a non-technical business owner without dumbing it down or drowning them
- The judgment to know when something is off, and the persistence to keep digging
- A reliable home internet connection and a private, quiet workspace suitable for handling sensitive client data
- Willingness to work rotating shifts, including nights, weekends, and holidays
- Ability to pass a background check
How you got there is up to you. A cybersecurity degree, a Security+ or CySA+, a home lab, a help desk background, military experience, or a bootcamp plus real self-study all count. We care about what you can do, not which box you checked.
Bonus points for:
- Hands-on or coursework exposure to a SIEM — Securonix, Microsoft Sentinel, CrowdStrike, Splunk, or similar
- Hands-on or coursework exposure to an EDR platform — SentinelOne, CrowdStrike, Huntress, Carbon Black, Defender, or similar
- Certifications such as Security+, CySA+, BTL1, GCIH, or CEH
- Scripting for repetitive work (PowerShell, Python, KQL)
- Prior MSP or MSSP experience — you already know what juggling multiple client environments feels like
If you meet most of this but not all of it, apply anyway. Tier 1 is where we train people.
Shifts
Our SOC runs 24x7x365 on rotating 8-hour shifts:
Shift preference is discussed during the interview. We do our best to match preference, and shift changes open up as the team grows.
What we provide
- Fully remote work — our SOC has been 100% remote since day one, not as a pandemic holdover
- All equipment provided
- [PTO and paid holidays]
- Direct access to senior analysts, threat hunters, and our IR team — not a ticket queue between you and expertise
Where this goes
Tier 1 is the entry point, not the ceiling. Analysts here have moved into Tier 2 investigation, threat hunting, digital forensics and incident response, detection engineering, and client-facing security consulting. We promote from within and we'd rather grow the analyst who already knows our clients than hire around them.
About VDA Labs
VDA Labs is a Michigan-based cybersecurity firm helping organizations of all sizes monitor, detect, and respond to cyber threats. We deliver Managed Detection and Response, Threat Hunting, Digital Risk Protection, and Incident Response — tailored to each client's actual risk profile rather than a one-size-fits-all package.
Our clients range from regional manufacturers and healthcare practices to school districts, tribal gaming operations, and financial institutions. That variety means the alerts you work are genuinely different week to week.
How to apply
Send your resume and a short note about why security interests you. No cover letter required — a few honest paragraphs beat a template.
Our process:
- Application review
- 30-minute intro call with our hiring lead
- Technical conversation with a senior SOC analyst — a discussion about how you think through an investigation, not a trivia quiz
- Final conversation with SOC leadership
- Offer
We aim to move from application to offer in under three weeks and to give every candidate who reaches the technical conversation a real answer either way.
VDA Labs is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other protected characteristic.
Pay: $20.00 - $25.00 per hour
Benefits:
Work Location: Remote