Role overview
About this role
The Office of the CISO is responsible for protecting IBM's systems, data, and global operations from cybersecurity threats. Our organization encompasses the full spectrum of cyber defense capabilities, including Threat Detection, Security Operations, Incident Response, Vulnerability Management, Endpoint Security, Product Security, Cloud Security, and Security Engineering. The Security Operations Center (SOC) serves as the front line of IBM's cyber defense mission. Operating 24x7 across a global environment, the SOC detects, analyzes, and responds to security events affecting IBM's users, devices, applications, and infrastructure. We are seeking a highly motivated Security Operations Center Analyst to join our SOC Team. This team is responsible for validating alerts, investigating suspicious activity, performing initial threat containment, and escalating confirmed security incidents. Successful candidates will possess a strong security operations mindset, excellent analytical skills, and the ability to make sound decisions in fast-paced operational environments. As a SOC Analyst, you will serve as a first responder to cybersecurity threats, helping protect IBM's global enterprise by identifying, investigating, and containing malicious activity before it becomes a significant incident. You will work closely with threat detection engineers, incident responders, security operations teams, and business stakeholders to assess security alerts, determine risk and impact, and take appropriate response actions. This role requires strong investigative instincts, technical troubleshooting skills, and the ability to communicate findings clearly to both technical and non-technical audiences. Key Responsibilities Monitor and investigate security alerts generated from SIEM, EDR, email security, cloud security, and network security platforms Perform triage and analysis of security events to determine legitimacy, severity, scope, and impact Execute approved containment actions, including host isolation, account restrictions, malicious email remediation, and blocking indicators of compromise Escalate confirmed or high-risk incidents while providing complete investigative context and supporting evidence Analyze endpoint, network, identity, cloud, and application telemetry to identify malicious activity Correlate data from multiple security technologies to investigate complex security events Document investigations, containment actions, and recommendations in accordance with operational procedures Participate in incident response activities and support post-incident reviews as needed Continuously improve detection and triage processes through operational feedback and collaboration with engineering teams Maintain awareness of emerging threats, attacker tactics, techniques, and procedures (TTPs), and industry trends Contribute to operational readiness by assisting with playbook development, process improvement, and knowledge sharing Experience in a Security Operations Center (SOC), Cybersecurity Operations, Incident Response, or related cybersecurity role Experience investigating and triaging security alerts in a large enterprise environment Experience using EDR platforms Experience working with SIEM platforms and log analysis technologies Understanding of common cyber threats, attacker methodologies, and MITRE ATT&CK techniques Experience performing threat containment actions and supporting incident response activities Strong analytical and problem-solving skills with attention to detail Experience analyzing endpoint, identity, email, network, and cloud-based security events Knowledge of Windows, Linux, macOS, Active Directory, Entra ID, and enterprise authentication technologies Working knowledge of networking fundamentals including DNS, TCP/IP, HTTP/S, firewalls, proxies, VPNs, and IDS/IPS technologies Ability to assess risk and prioritize multiple investigations simultaneously in a fast-paced operational environment Strong verbal communication, technical writing, and incident documentation skills Ability to work independently while collaborating effectively across global teams Key Technical Skills Security Alert Triage and Investigation Event Correlation and Threat Analysis Endpoint Detection and Response (EDR) Security Information and Event Management (SIEM) Account Compromise Investigation Phishing and Business Email Compromise Analysis Threat Containment and Remediation Log Analysis and Query Development Threat Intelligence Utilization Incident Documentation and Case Management Experience working within an enterprise SOC supporting global operations Experience using QRadar, Splunk, Sentinel, Elastic, or similar SIEM platforms Experience with CrowdStrike Falcon and/or Microsoft Defender XDR Familiarity with cloud security monitoring in AWS, Azure, IBM Cloud, or GCP environments Experience performing threat hunting activities Knowledge of identity-based attacks and Entra ID / Active Directory investigations Understanding of malware behavior and attacker TTPs Experience developing detections, use cases, or automation workflows Basic scripting skills using Python, PowerShell, KQL, or similar technologies Experience supporting incident response engagements or working closely with a CSIRT organization Cybersecurity certifications such as Security+, CySA+, GCIH, GCIA, GCED, SC-200, SC-300, or equivalent experience