1

Associate Soc Analyst Jobs in California (NOW HIRING)

Program Associate

San Francisco, CA · On-site

$28.85 - $31.25/hr

... Analyst and the Senior Manager of Business Applications SOC 3075 Forms Processing (Zendesk ... Associate's degree in a related field preferred; we also warmly welcome applicants possessing ...

Program Associate

San Francisco, CA · On-site

$28.85 - $31.25/hr

... Analyst and the Senior Manager of Business Applications SOC 3075 Forms Processing (Zendesk ... Associate's degree in a related field preferred; we also warmly welcome applicants possessing ...

Works with the Security Operations Center (SOC) to leverage data from monitoring and alerts ... Associate's degree and 4+ years of incident response or digital forensics experience or Bachelor ...

Responsible for internal SOC/part demand roll up for all milestones * Partner with technical and ... OR Associate's degree and 2+ years of relevant work experience. OR High School Diploma or ...

Senior Program Analyst

San Diego, CA · On-site

$123K - $123K/yr

Minimum Qualifications: • Associate's degree in Business Administration, Management, Computer ... Tracks the progress and execution of SOC chip deliverables to ensure deadlines are met and ...

Senior Program Analyst

San Diego, CA · On-site

$123K - $123K/yr

Tracks the progress and execution of SOC chip deliverables to ensure deadlines are met and ... • Associate's degree in Business Administration, Management, Computer Science, Engineering ...

next page

Showing results 1-20

Associate Soc Analyst information

See California salary details

$28.6K

$72.7K

$123.9K

How much do associate soc analyst jobs pay per year?

As of Aug 21, 2026, the average yearly pay for associate soc analyst in California is $72,689.00, according to ZipRecruiter salary data. Most workers in this role earn between $55,300.00 and $80,400.00 per year, depending on experience, location, and employer.

What is an associate SOC analyst?

An Associate SOC (Security Operations Center) Analyst is an entry-level cybersecurity professional responsible for monitoring, detecting, and responding to security threats. They analyze alerts from security tools, investigate potential incidents, and escalate threats as needed. Their role helps protect an organization's systems and data from cyber-attacks by ensuring a swift response to security breaches. Strong analytical skills, knowledge of security tools, and attention to detail are essential for success in this role.

What are the typical daily responsibilities of an associate SOC analyst?

As an Associate SOC Analyst, your day-to-day responsibilities typically involve monitoring security alerts, investigating potential threats, documenting incidents, and escalating issues according to established procedures. You’ll work closely with senior analysts, IT staff, and occasionally other departments to help coordinate response efforts and maintain system security. Routine activities may include reviewing logs, performing initial triage of incidents, and contributing to ongoing security improvements. This role is collaborative and detail-oriented, providing essential frontline support to safeguard organizational networks against cyber threats.

What are the key skills and qualifications needed to thrive as an associate SOC analyst?

To excel as an Associate SOC Analyst, you need foundational knowledge of cybersecurity concepts, incident detection, and analysis, often supported by a relevant degree or certifications such as CompTIA Security+ or Cisco's CCNA Security. Experience with Security Information and Event Management (SIEM) tools, intrusion detection systems, and ticketing platforms is highly valuable in this role. Strong analytical thinking, attention to detail, and clear communication are important soft skills to effectively interpret security alerts and collaborate within a team. These skills ensure thorough monitoring, timely response to threats, and effective coordination that help protect organizational assets.

Is associate SOC analyst still in demand?

The associate SOC analyst role remains in demand due to the increasing need for cybersecurity monitoring and threat detection. Employers seek candidates with knowledge of security tools, incident response, and certifications like CompTIA Security+ or Cisco CyberOps. The role offers opportunities for career growth in cybersecurity teams across various industries.

What are the most commonly searched types of Soc Analyst jobs in California?

The most popular types of Soc Analyst jobs in California are:

What are popular job titles related to Associate Soc Analyst jobs in California?

For Associate Soc Analyst jobs in California, the most frequently searched job titles are:

What job categories do people searching Associate Soc Analyst jobs in California look for?

The top searched job categories for Associate Soc Analyst jobs in California are:

What cities in California are hiring for Associate Soc Analyst jobs?

Cities in California with the most Associate Soc Analyst job openings:

Infographic showing various Associate Soc Analyst job openings in California as of August 2026, with employment types broken down into 1% As Needed, 74% Full Time, 23% Part Time, 1% Temporary, and 1% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution, with an average salary of $72,689 per year, or $34.9 per hour.

SOC THREAT DETECTION & INCIDENT RESPONSE ANALYST

TECH-NET, INC

Folsom, CA • On-site

Other

Posted 7 days ago


Job description

SOC THREAT DETECTION & INCIDENT RESPONSE ANALYST
Job Title: SOC Threat Detection & Incident Response Analyst
Location: Remote
Position Type: Full-Time / Contract-to-Hire
Operational Shift: Monday – Friday, 7:00 AM – 6:30 PM PST (Coverage shift model)
 
1. Role Overview
Technet is seeking a SOC Threat Detection & Incident Response Analyst to provide active security monitoring, threat detection, incident triage, and response for a critical energy-sector utility billing and data management platform.
In this role, you will be responsible for active triage and correlation across CrowdStrike Falcon, a centralized Wazuh SIEM, AWS-native security services (GuardDuty, Security Hub, WAF), and application middleware. You will execute incident response actions and proactive threat hunts in strict alignment with utility emergency operations and incident response frameworks (CEOP/CIRP).
2. Technical Stack & Systems Monitored
  • Detection & SIEM Tools: Wazuh SIEM Dashboard & Correlation Engine, CrowdStrike Falcon (Falcon Console, FDR / Streaming API Telemetry).
  • Cloud Security Telemetry: Amazon GuardDuty, AWS Security Hub, AWS WAF, AWS CloudTrail, VPC Flow Logs, Route 53 Resolver logs.
  • Application & Data Tiers: Amazon RDS SQL Server audit logs, Windows Event Logs / IIS web logs, Dell Boomi middleware logs, GoAnywhere MFT transfer logs, Salesforce CRM connector logs.
  • Posture & Vulnerability Feeds: Wazuh SCA (Security Configuration Assessment), AWS Systems Manager (SSM) vulnerability findings, Containerized Prowler daily compliance reports.
  • Operational Frameworks: SOC 2 Type II controls, NIST CSF, and NIST 800-53.
3. Key Responsibilities
  • Active SOC Monitoring & Triage: Monitor cloud, endpoint, network, and application security alerts Monday through Friday (7:00 AM – 6:30 PM PST), adhering to strict SLAs (≤ 15 minutes for Critical severity; ≤ 1 hour for High severity).
  • Multi-Stage Threat Correlation: Correlate disparate signals across CrowdStrike Falcon endpoint detections, AWS GuardDuty anomalies, CloudTrail management events, IIS web server logs, and RDS SQL Server audit records to identify complete attack chains.
  • Threat Hunting: Conduct hypothesis-driven and intelligence-driven threat hunts focusing on cloud credential hijacking, IAM privilege escalation, impossible-travel anomalies, MFA bypass, and unauthorized data staging/exfiltration.
  • Integration Edge & File Transfer Monitoring: Perform targeted monitoring of GoAnywhere MFT, Dell Boomi, and external data exchanges (PG&E feeds) for anomalous file transfers, off-hours execution, or unauthorized outbound connections.
  • Incident Response & Containment: Execute response playbooks aligned with enterprise CEOP and CIRP frameworks. Perform host isolation recommendations, credential revocation coordination, and initial evidence preservation.
  • Vulnerability & Posture Prioritization: Review daily vulnerability scan outputs from Wazuh SCA/SSM and posture findings from Prowler; prioritize findings by business impact and exploitability, and track remediation with engineering teams.
  • Reporting & Governance: Assist in preparing monthly security posture reviews, threat intelligence summaries, and quarterly executive risk dashboards.
4. Required Qualifications & Technical Skills
  • Experience: 3+ years of hands-on experience in a Security Operations Center (SOC), Threat Analysis, or Incident Response role.
  • Tooling Proficiency: Direct experience analyzing alerts and querying logs within CrowdStrike FalconWazuh (or ELK/OpenSearch/Splunk SIEM), and AWS Security Hub / GuardDuty.
  • Cloud & Identity Threat Knowledge: Practical experience analyzing AWS CloudTrail logs, detecting IAM abuse patterns, credential spraying, and web application attack vectors (OWASP Top 10, AWS WAF rules).
  • Log Analysis Skills: Strong ability to inspect and analyze raw logs from Windows Event Viewer, IIS web servers, database audit logs (SQL Server), and API/MFT transactional logs.
  • Incident Response Execution: Understanding of formal incident response methodologies (containment, eradication, recovery) and playbook execution.
  • U.S. Data Residency Requirement: Must reside and work exclusively within the United States.
5. Preferred Qualifications & Certifications
  • CompTIA CySA+, Security+, or GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Enterprise Defender (GCED) or GIAC Cloud Forensics (GCFA)
  • Certified Information Systems Security Professional (CISSP) or CISM
  • AWS Certified Cloud Practitioner or AWS Certified Solutions Architect Associate
  • Prior experience in utility, public power, or critical infrastructure operations.