1

Csoc Analyst Jobs (NOW HIRING)

Report and escalate security incidents to CSOC leadership. * Support alert tuning, detection improvements, threat-intelligence integration, and false-positive analysis. * Perform vulnerability ...

Senior Cyber Security Analyst

Springfield, VA · On-site

$104K - $134K/yr

Providing leadership and advanced Cyber Security Operations Center (CSOC) support, managing cyber ... Performing cyber engineering trend analysis, producing detailed reports, and supporting 24x7 ...

Senior Cyber Security Analyst

Springfield, VA · On-site

$104K - $134K/yr

Providing leadership and advanced Cyber Security Operations Center (CSOC) support, managing cyber ... Performing cyber engineering trend analysis, producing detailed reports, and supporting 24x7 ...

Reports and escalates to the CSOC Team Lead and/or SOC Manager. * Supports the continuous ... Security event analysis and threat triage. * Correlating and interpreting data from multiple ...

Senior Cyber Security Analyst

Springfield, MA · On-site

$99K - $128K/yr

Providing leadership and advanced Cyber Security Operations Center (CSOC) support, managing cyber ... Performing cyber engineering trend analysis, producing detailed reports, and supporting 24x7 ...

Reports and escalates to the CSOC Team Lead and/or SOC Manager. * Supports the continuous ... Security event analysis and threat triage. * Correlating and interpreting data from multiple ...

Analyze large datasets to identify patterns and anomalies indicative of malicious activities ... Collaborate with other CSOC team members and stakeholders to respond to and investigate security ...

Showing results 21-40

Csoc Analyst information

See salary details

$49K

$88.6K

$123.5K

How much do csoc analyst jobs pay per year?

As of Sep 14, 2026, the average yearly pay for csoc analyst in the United States is $88,569.00, according to ZipRecruiter salary data. Most workers in this role earn between $64,000.00 and $99,500.00 per year, depending on experience, location, and employer.

What is a CSOC analyst?

A CSOC Analyst, or Cyber Security Operations Center Analyst, is a professional responsible for monitoring, detecting, and responding to cybersecurity threats within an organization. They analyze security events, investigate incidents, and help protect the organization's information assets from cyberattacks. CSOC Analysts use various security tools and technologies to identify vulnerabilities and ensure compliance with security policies. Their role is critical in maintaining a secure IT environment and minimizing the risk of data breaches.

What are the key skills and qualifications needed to thrive as a CSOC analyst, and why are they important?

To thrive as a CSOC Analyst, you need a strong understanding of cybersecurity principles, threat detection, incident response, and typically a degree in computer science or a related field. Familiarity with Security Information and Event Management (SIEM) tools, intrusion detection systems, and certifications like CompTIA Security+, CEH, or CISSP are commonly required. Analytical thinking, attention to detail, and effective communication are vital soft skills for excelling in this role. These skills are essential for quickly identifying, analyzing, and mitigating cyber threats to protect organizational assets and maintain security compliance.

What are the most common challenges a CSOC analyst faces in monitoring and responding to security incidents?

CSOC Analysts often encounter challenges such as distinguishing between true threats and false positives, managing a high volume of alerts, and staying up-to-date with evolving attack techniques. The fast-paced environment requires quick decision-making and effective communication with both technical and non-technical teams. Over time, analysts develop a keen eye for patterns and improve their incident response skills, which can lead to advancement into senior analyst or management roles within cybersecurity operations.

What is the difference between Csoc Analyst vs Security Analyst?

AspectCsoc AnalystSecurity Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentSecurity Operations Center (SOC), monitoring security alertsVarious environments including SOC, corporate, or consulting firms
Industry UsagePrimarily in cybersecurity and IT firms with SOC teamsBroader, including corporate security, government, and private sectors

Both Csoc Analysts and Security Analysts share similar certifications and often work in security operations centers. However, Csoc Analysts typically focus on monitoring and managing security alerts within a SOC environment, while Security Analysts may work across diverse settings, including policy development and incident response outside of SOCs. The roles are closely related, with Csoc Analysts often serving as a specialized subset of Security Analysts.

Do CSOC analysts get paid well?

CSOC analysts typically earn competitive salaries that vary based on experience, certifications, and location. Entry-level positions may start lower, but experienced analysts with skills in security tools and incident response can command higher pay, often supplemented by overtime and shift differentials in 24/7 security operations centers.

How much is a CSOC analyst paid?

A CSOC analyst's salary typically ranges from $60,000 to $100,000 annually, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced analysts with specialized skills can earn higher salaries, often with opportunities for overtime and shift differentials in 24/7 security operations centers.

Is CSOC analyst still in demand?

CSOC analysts are in high demand due to the increasing need for cybersecurity monitoring and incident response across organizations. They typically require skills in security tools, threat detection, and certifications like CISSP or CEH, making this a stable and growing career field.

What cities are hiring for Csoc Analyst jobs?

Cities with the most Csoc Analyst job openings:

What states have the most Csoc Analyst jobs?

States with the most job openings for Csoc Analyst jobs include:

What are popular job titles related to Csoc Analyst jobs?

For Csoc Analyst jobs, the most frequently searched job titles are:

CSOC Incident Response Lead

Cleveland, OH • On-site

Sherwin-Williams
Construction Materials Wholesalers • 10K+ employees

Full-time

Medical, Retirement

Posted 17 days ago


Sherwin-Williams rating

7.6

Company rating: 7.6 out of 10

Based on 691 frontline employees who took The Breakroom Quiz


Job description

The Cybersecurity Security Operations Center (CSOC) Incident Response (IR) Lead is a cybersecurity professional responsible for overseeing and coordinating the response to all security incidents within the organization, acting as the primary decision-maker during a breach by leading the incident response team, assessing the situation, implementing response plans, and communicating updates to stakeholders throughout the incident lifecycle, with the primary goal of minimizing risk and restoring operations quickly and safely. This role requires a strategic thinker with strong leadership and technical skills, capable of making quick and informed decisions in high-pressure situations. Ability to support the IR lifecycle using our Security Information and Event Monitoring (SIEM) and Security Orchestration and Automated Response (SOAR) technologies.

This role reports directly to the CSOC manager.

At Sherwin-Williams, our purpose is to inspire and improve the world by coloring and protecting what matters. Our paints, coatings and innovative solutions make the places and spaces in our world brighter and stronger. Your skills, talent and passion make it possible to live this purpose, and for customers and our business to achieve great results. Sherwin-Williams is a place that takes its stability, growth and momentum and translates it to possibility for our people. Our people are behind the strength of our success, and we invest and support you in:

Life ... with rewards, benefits and the flexibility to enhance your health and well-being
Career ... with opportunities to learn, develop new skills and grow your contribution
Connection ... with an inclusive team and commitment to our own and broader communities
It's all here for you... let's Create Your Possible

At Sherwin-Williams, part of our mission is to help our employees and their families live healthier, save smarter and feel better. This starts with a wide range of world-class benefits designed for you. From retirement to health care, from total well-being to your daily commute-it matters to us. A general description of benefits offered can be found at http://www.myswbenefits.com/. Click on "Candidates" to view benefit offerings that you may be eligible for if you are hired as a Sherwin-Williams employee.

Compensation decisions are dependent on the facts and circumstances of each case and will impact where actual compensation may fall within the stated wage range. The wage range listed for this role takes into account the wide range of factors considered in making compensation decisions including skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. The wage range, other compensation, and benefits information listed is accurate as of the date of this posting. The Company reserves the right to modify this information at any time, with or without notice, subject to applicable law.

Qualified applicants with arrest or conviction records will be considered for employment in accordance with applicable federal, state, and local laws including with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act where applicable.

Sherwin-Williams is proud to be an Equal Employment Opportunity employer. All qualified candidates will receive consideration for employment and will not be discriminated against based on race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, age, pregnancy, genetic information, creed, marital status or any other consideration prohibited by law or by contract.

As a VEVRAA Federal Contractor, Sherwin-Williams requests state and local employment services delivery systems to provide priority referral of Protected Veterans.

Please be aware, Sherwin-Williams recruiting team members will never request a candidate to provide a payment, ask for financial information, or sensitive personal information like national identification numbers, date of birth, or bank account numbers during the application process.

Education & Experience

Required:

  • Bachelor's degree in computer science, Information Technology, or related field (or equivalent experience).
  • 8+ years IT/Cybersecurity experience.
  • Proven experience leading and coordinating IR efforts in a fast-paced environment.
  • Strong technical knowledge of network security, malware analysis, intrusion detection, and related technologies.
  • Excellent communication and interpersonal skills, with the ability to interact effectively with stakeholders at all levels and explain technical information to non-technical stakeholders.
  • Ability to remain calm and focused under pressure, with a commitment to delivering results.
  • Understanding of various operating systems (z/OS, Window, UNIX, Linux, AIX, etc.).
  • Must be eighteen years or older
  • Must be legally authorized to work in the United States without company sponsorship

Preferred Experience

  • Relevant certifications such as the GIAC Incident Handler (GCIH) are preferred.
  • Previous experience with IR and handling
  • Deep understanding of cybersecurity concepts, including incident response methodologies and threat intelligence
  • Familiarity with relevant cybersecurity frameworks and regulations (e.g., NIST, GDPR)
  • SIEM/SOAR solutions, such as Splunk and Sumo Logic.
  • CSOC or working with a Managed Security Service Provider.
  • Threat Intelligence Platform (TIP) and importance of integrating into the SIEM in support of IR and Indicators of Compromise.
  • Exposure to Incident Response in the Operational Technology domain.

Serve as the primary point of contact and decision-maker during cybersecurity incidents.

Assist in utilization of full CSOC toolset in support of IR (i.e. SIEM / SOAR, sandbox, email security, End Point Detection and Response, etc.)

Lead and coordinate incident response efforts within the Triage & Response team, including mobilizing resources, assessing the situation, and implementing response plans.

Collaborate with internal and external stakeholders to gather information, assess impact, and prioritize response actions.

Provide clear and timely communication to stakeholders, including executive leadership, throughout the incident lifecycle.

Implement and refine the analysis and forensics process.

Implement and refine incident response procedures, protocols, and playbooks to enhance effectiveness and efficiency.

Conduct monthly post-incident reviews to help identify lessons learned, areas for improvement, and enforce consistent action item remediation with analysts, engineers, and relevant stakeholders.

Stay abreast of emerging cyber threats, vulnerabilities, and best practices in incident response through collaboration with Vulnerability management and Cyber Threat Intelligence teams.

Hold monthly workshops with stakeholders from Information Technology and Operational Technology to discuss on-going and future initiatives related to Incident Response.

Collaborate with security engineers to enhance detection and playbook automation.

Lead tabletop exercises with CSOC team members and internal stakeholders to facilitate training, identify gaps, and support continuous improvement.

Assist with managing the IR database to ensure adherence to audit and compliance requirements.

Support CSOC manager with vendor management of the IR retainer(s).

Oversee formal / informal IR training. Identify training opportunities with unused IR retainer credits.

This is a remote position.

This position is not eligible for sponsorship for work authorization now or in the future, including conversion to H1-B visa. Must be legally authorized to work in the country of employment without needing sponsorship for employment work visa status now or in the future.

Job duties include contact with other employees and access confidential and proprietary information and/or other items of value, and such access may be supervised or unsupervised. TheCompany therefore has determined that a review of criminal history is necessary to protect the business and its operations and reputation and is necessary to protect the safety of the Company's staff, employees, and business relationships.


What Sherwin-Williams employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom