International Business Machines Corp logo

Security Operations Center Analyst

    Highlights

    You will work closely with threat detection engineers, incident responders, security operations teams, and business stakeholders to assess security alerts, determine risk and impact, and take appropriate response actions. As a SOC Analyst, you will serve as a first responder to cybersecurity threats, helping protect IBM's global enterprise by identifying, investigating, and containing malicious activity before it becomes a significant incident.

    Numbers & Facts

    LocationAustin, TX
    IndustryComputer/IT Services
    Company Size10,000 employees or more
    Year Founded1911
    Websitehttp://www-03.ibm.com/employment/us/

    Description

    As a SOC Analyst, you will serve as a first responder to cybersecurity threats, helping protect IBM's global enterprise by identifying, investigating, and containing malicious activity before it becomes a significant incident.

    You will work closely with threat detection engineers, incident responders, security operations teams, and business stakeholders to assess security alerts, determine risk and impact, and take appropriate response actions.

    This role requires strong investigative instincts, technical troubleshooting skills, and the ability to communicate findings clearly to both technical and non-technical audiences.

    Key Responsibilities

    • Monitor and investigate security alerts generated from SIEM, EDR, email security, cloud security, and network security platforms
    • Perform triage and analysis of security events to determine legitimacy, severity, scope, and impact
    • Execute approved containment actions, including host isolation, account restrictions, malicious email remediation, and blocking indicators of compromise
    • Escalate confirmed or high-risk incidents while providing complete investigative context and supporting evidence
    • Analyze endpoint, network, identity, cloud, and application telemetry to identify malicious activity
    • Correlate data from multiple security technologies to investigate complex security events
    • Document investigations, containment actions, and recommendations in accordance with operational procedures
    • Participate in incident response activities and support post-incident reviews as needed
    • Continuously improve detection and triage processes through operational feedback and collaboration with engineering teams
    • Maintain awareness of emerging threats, attacker tactics, techniques, and procedures (TTPs), and industry trends
    • Contribute to operational readiness by assisting with playbook development, process improvement, and knowledge sharing

    About Company

    At IBM, you don’t need a degree to shape the future. Just bring your skills—and your passion. To build. To design. To code. To consult. To think along with clients and sell. To make markets. To invent. To collaborate.

    Not just to do something better, but to attempt things you've never thought possible. To lead in this new era of technology and solve some of the world's most challenging problems. Let’s get to work.