1

Soc Watch Analyst Jobs (NOW HIRING)

$125 - $150/hr

The Detection Engineer collaborates with Defensive Cyber Operations (DCO) Watch Analysts and other ... Required Experience: * 5+ years of experience working in a CSSP, SOC, or similar environment. * 2+ ...

Senior SOC Analyst

Cincinnati, OH · On-site

$95K - $125K/yr

Job Title: Senior SOC Analyst Location: Cincinnati, OH (Hybrid / Remote eligible based on ... Prior SOC or CSIRT experience on a 24x7 watch desk. * Working knowledge of attacker tooling ...

Senior SOC Analyst

Cincinnati, OH · On-site

$100 - $125/hr

Job Title: Senior SOC Analyst Location: Cincinnati, OH (Hybrid / Remote eligible based on ... Prior SOC or CSIRT experience on a 24x7 watch desk. * Working knowledge of attacker tooling ...

Senior SOC Analyst

Cincinnati, OH · On-site +1

$95K - $125K/yr

Job Title: Senior SOC Analyst Location: Cincinnati, OH (Hybrid / Remote eligible based on ... Prior SOC or CSIRT experience on a 24x7 watch desk. * Working knowledge of attacker tooling ...

Senior SOC Analyst

Cincinnati, OH · On-site

$95K - $125K/yr

In this role, you will act as a lead analyst on the floor, owning the assessment of security events ... Prior SOC or CSIRT experience on a 24x7 watch desk.Working knowledge of attacker tooling, malware ...

Demonstrated experience in a supervisory or team lead capacity overseeing SOC analysts or watch ... floor operations * Active Secret clearance required Technical & Domain Capabilities * Deep ...

Showing results 41-60

Soc Watch Analyst information

See salary details

$5

$33

$75

How much do soc watch analyst jobs pay per hour?

As of Sep 9, 2026, the average hourly pay for soc watch analyst in the United States is $33.04, according to ZipRecruiter salary data. Most workers in this role earn between $20.43 and $38.46 per hour, depending on experience, location, and employer.

What is the difference between Soc Watch Analyst vs Security Analyst?

AspectSoc Watch AnalystSecurity Analyst
CredentialsCertifications like CompTIA Security+, CEH often preferredSimilar certifications, often including CISSP, Security+
Work EnvironmentMonitoring security alerts in SOC environment, shift work commonAnalyzing security threats, risk assessment, often office-based
Employer & IndustryTypically employed by cybersecurity firms, large corporations, government agenciesEmployers include corporations, government, consulting firms

Both roles focus on cybersecurity, with Soc Watch Analysts primarily monitoring security alerts in a Security Operations Center, while Security Analysts analyze threats and develop security strategies. The roles overlap in certifications and work environment, but Soc Watch Analysts are more alert-focused, whereas Security Analysts engage in broader security analysis and planning.

What states have the most Soc Watch Analyst jobs?

States with the most job openings for Soc Watch Analyst jobs include:

What are popular job titles related to Soc Watch Analyst jobs?

For Soc Watch Analyst jobs, the most frequently searched job titles are:

Infographic showing various Soc Watch Analyst job openings in the United States as of September 2026, with employment types broken down into 1% Internship, 88% Full Time, 6% Part Time, 1% Temporary, and 4% Contract. Highlights an 81% Physical, 7% Hybrid, and 12% Remote job distribution, with an average salary of $68,733 per year, or $33 per hour.

Detection Analyst (Elastic)

On-site

BreakPoint Labs LLC
Network Security • 11 - 50 employees

$125 - $150/hr

Other

Posted 7 days ago


Key responsibilities

  • Develop, implement, and maintain custom detection rules and logic in the Elastic Security platform targeting adversary TTPs.

  • Collaborate with DCO Watch Analysts to integrate detection mechanisms into monitoring and incident response workflows.

  • Maintain and update detection tools and signatures in response to evolving threats and ensure compliance with applicable directives.


Job description

BreakPoint Labs is seeking a Detection Engineer with an expertise in Elastic to design, develop, and implement detection mechanisms to identify cyber threats within a Cybersecurity Service Provider (CSSP) environment. The candidate will focus on creating and managing IDS/IPS signatures, log correlation rules, and other detection tools based on indicator lifecycle analysis. The Detection Engineer collaborates with Defensive Cyber Operations (DCO) Watch Analysts and other teams to ensure timely and effective threat detection, adhering to CJCSM 6510.01B reporting requirements and supporting the CSSP’s mission to protect data across a wide spectrum of sources and locations.

Responsibilities include:
  • Develop, implement, and maintain custom, high-fidelity detection rules and logic in the Elastic Security platform specifically targeting adversary TTPs mapped to the MITRE ATT&CK® framework.
  • Develop and prioritize risk-based alerting mechanisms to focus detection efforts on high-impact threats, aligning with organizational risk assessments.
  • Analyze threat intelligence to create and refine detection mechanisms tailored to the customer’s environment.
  • Validate and test detection rules to ensure accuracy, minimize false positive and benign positive matches, and enhance threat identification capabilities.
  • Collaborate with DCO Watch Analysts to integrate detection mechanisms into monitoring and incident response workflows.
  • Maintain and update detection tools and signatures in response to evolving threats, ensuring compliance with CJCSM 6510.01B and other applicable directives.
  • Compile and maintain internal standard operating procedure (SOP) documentation for detection creation and implementation processes.
  • Coordinate with reporting agencies and subscriber sites to align detection strategies with operational needs and threat intelligence.
  • Participate in program reviews, product evaluations, and onsite certification evaluations to assess detection tool efficacy.
  • Overtime may be required to support detection implementation or incident response actions (Surge).
  • Up to 10% travel may be required.
Required Experience:
  • 5+ years of experience working in a CSSP, SOC, or similar environment.
  • 2+ years of experience with signature development, detection logic creation and optimization on multiple platforms.
  • Experience in threat detection engineering, threat hunting, or a related role with hands-on experience using the Elastic Stack, Kibana Query Language (KQL), Event Query Language (EQL), Elasticsearch Query Language (ES|QL) and/or Elastic Defend.
  • Experience with threat intelligence platforms and indicator management.
  • Proficient knowledge of detection creation and implementation processes.
  • Expertise in IDS/IPS solutions, including signature development and optimization.
  • Strong understanding of the indicator lifecycle, including initial discovery, development, operational maturity, and long-term sustainment.
  • Effective verbal and written communication skills.
  • Ability to solve complex problems independently.
  • Preferred certifications: Elastic Certified Analyst; Elastic Certified SIEM Analyst, Elastic Certified Engineer.

Certifications Required: DoD 8570 IAT Level II and DoD 8140 CSSP-specific certification.

Security Clearance Required: DoD Secret Clearance.

Education Required: Bachelor’s Degree Area(s) of Study of relevant discipline and 5 years of experience. OR, at least 8 years of experience working in a CSSP, SOC, or similar.

#J-18808-Ljbffr