Skip to content
← Back to job listings

Level 1 SOC Analyst

Defendify · Portland, ME

Imported listingfull-time16 days ago

About The Role

Stand watch over the customers who count on us and turn suspicious activity into fast, informed action.
We're looking for a curious, attention to detail-oriented Level 1 SOC Analyst to join Defendify's Security Operations Center team. You'll monitor and triage cybersecurity alerts, investigate suspicious activity, document what you find, and quickly escalate incidents that require deeper analysis or response.
This is a full-time third shift, primarily in-office role at our Portland Maine headquarters. Because our Security Operations Center supports customers around the clock, alternating shift work may be required.
The Role
Defendify helps small and midsized organizations build stronger cybersecurity without managing a collection of segregated products and providers. Our All-In-One Cybersecurity platform brings together 13 modules across assessment and testing, policies and training, and detection and response.
As a Level 1 SOC Analyst, you'll help watch over customer environments 24/7. You'll serve as the first line of human analysis, reviewing signals, gathering context, deciding whether activity is benign or suspicious, and making sure potential threats reach the right people with useful information. You'll work from established playbooks, learn from experienced security professionals, and build the judgment and communication skills needed to progress in security operations.
What You'll Own
Monitor and triage cybersecurity alerts and events across customer environments
Review logs and available context to identify suspicious patterns, false positives, and activity that requires deeper investigation
Document findings, dispositions, and supporting evidence clearly and consistently in each case
Escalate incidents promptly and accurately according to established procedures and severity criteria
Support clean shift handoffs so active investigations and customer-impacting issues continue without losing context
Collaborate with senior analysts and security leaders during investigations and incident response
Follow operational playbooks while identifying opportunities to improve alert handling, documentation, and team workflows
Continue building knowledge of threats, attack techniques, security tools, and customer environments
How We Work
Our analysts work with modern security platforms, automation, and AI-assisted investigation to move quickly and focus attention where human judgment matters most. The tools accelerate the work, but our analysts remain accountable for validating evidence, making sound decisions, documenting their reasoning, and escalating with useful context.
Security operations is a team sport. We communicate clearly, ask for help when the evidence is incomplete, and treat a strong handoff as part of the investigation itself. Accuracy matters. So does speed. The goal is to make the right decision quickly and give the next analyst what they need to act.
What Success Looks Like
Alerts are reviewed and triaged accurately within established response targets
Potential threats are escalated quickly with clear evidence, severity, and recommended next steps
Case notes are complete, concise, and useful to the analysts who continue the investigation
Playbooks and escalation procedures are followed consistently, with sound judgment when a situation falls outside the expected pattern
Shift handoffs are reliable, and important context is not lost between team members
Your technical knowledge, investigative confidence, and ability to handle increasingly complex alerts grow steadily over time
You Might Be a Fit If You
Have an associate's or bachelor's degree in cybersecurity, information technology, computer science, or a related field, or equivalent hands-on training and experience
Understand core cybersecurity concepts, common threats, and attack techniques
Are familiar with technologies such as SIEM platforms, endpoint protection, IDS or IPS, firewalls, and antivirus tools
Understand networking fundamentals, including TCP/IP, DNS, and HTTP/S
Can analyze logs and alerts, identify meaningful patterns, and recognize when an issue should be escalated
Write clearly, communicate calmly, and pay close attention to details
Are comfortable following defined procedures while asking thoughtful questions when the evidence does not fit the playbook
Can work effectively in a 24/7 operational environment where shift work may be required
Hold a relevant certification such as CompTIA Security+, Network+ or CySA+, or are actively working toward one; certifications are a plus, not a requirement

This is an external listing. JobSpring does not represent or verify the employer. Report this listing