SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Horizon3.ai is seeking a mid-level SOC Analyst to join its Security Operations team. The role involves monitoring and responding to security events across enterprise environments using SIEM platforms (Elastic SIEM preferred), with responsibility for log ingestion, alert triage, detection tuning, and incident response in cloud-native environments.
Key responsibilities include: monitoring SIEM health and effectiveness; supporting log ingestion, parsing, and normalization across AWS, Okta, endpoints, firewalls, and SaaS sources; building dashboards and KPIs to demonstrate security visibility; triaging and investigating alerts with escalation to senior analysts; tuning detection rules to reduce false positives; using MITRE ATT&CK frameworks to contextualize detections; analyzing logs across cloud, endpoint, network, and application sources; performing structured investigations and root cause analysis; following and refining incident response playbooks; contributing to SOAR automation (Tines or similar); leveraging LLM/AI-assisted tooling for triage and investigation enrichment; participating in threat hunting; and communicating findings to peers and stakeholders.
Required qualifications: 3–6 years of hands-on SOC or security analyst experience; proficiency with enterprise SIEM platforms (Elastic SIEM, Splunk, Microsoft Sentinel, or QRadar); solid grasp of log analysis, security telemetry, and event correlation; proficiency with detection-rule authoring and query languages (KQL, Lucene, SPL); scripting skills in Python, Bash, or PowerShell; familiarity with at least one major cloud platform (AWS, GCP, Azure) and its security tooling; working knowledge of MITRE ATT&CK, NIST, and CIS frameworks; practical experience with LLMs/AI assistants; strong analytical and problem-solving skills; and clear written and verbal communication. Bachelor's degree in Computer Science, Cybersecurity, Information Security, or related field, or equivalent hands-on security operations experience required.