aspenviewtech logo

SOC Analyst, Tier 1

aspenviewtech • LATAM


No Relocation

Posted: September 17, 2026

Job Description

 

Why Join AspenView?

At AspenView, we’re more than a nearshore IT partner—we’re a people-first, purpose-driven company that believes great culture drives great outcomes. We’re passionate about connecting talent and technology to deliver measurable value for clients—and meaningful career paths for our people.

Here’s what you can expect:

  • Competitive base
  • Flexible work model: hybrid, remote, or in-office
  • Real growth opportunities and leadership visibility
  • Inclusive, respectful culture that blends U.S. innovation with Colombian heart
  • A company that listens, invests in you, and celebrates wins together

The Tier 1 SOC Analyst is the critical first responder within the security operations team, monitoring a US higher-education client on a shift rotation. You are responsible for executing triage properly: working the alert, determining its validity, and either closing it with a justified note or escalating it cleanly so the next person has exactly what they need. You will never guess who owns a system, as each account has a named engineer behind it, and you will always have a Tier 2 analyst available on shift or on call to support you.

What you will do:

Alert Triage & Investigation

  • Own the first-line triage of every alert that reaches the queue during your shift, acting against each client's agreed severity tiers.

  • Conduct initial investigations by pulling logs, checking hosts, and reviewing accounts to establish whether a genuine event occurred.

  • Close non-actionable alerts with clear, detailed notes that stand up to later review.

Escalation & Collaboration

  • Deliver clean escalations; ensure that a Tier 2 analyst never has to redo your investigative work to understand the case.

  • Write comprehensive shift handovers so the incoming analyst can act immediately without requiring a phone call.

  • Actively improve the queue by flagging repetitive alerts (seen three times or more) to trigger detection rule changes.

Tools & Technologies:

  • SIEM Platforms: Hands-on experience with Microsoft Sentinel (preferred), Splunk, QRadar, or Elastic.

  • Frameworks: Working, practical knowledge of MITRE ATT&CK applied directly to real-world alerts.

  • Infrastructure: Solid networking, Windows, and Linux fundamentals to distinguish misconfigurations from actual intrusions.

What you bring:

  • Experience: Two or more years operating in a SOC, NOC, or comparable monitoring role.

  • Communication: English proficiency that holds up reliably in written notes and on 3am escalation calls.

  • Mindset: Diligent and team-oriented. You escalate early rather than sitting on a potential issue, and you value clean documentation.

  • Availability: Complete comfort with working rotating shifts, including nights and weekends, as a permanent working pattern.

Bonus Qualifications: Proficiency in KQL, Python, or PowerShell scripting; familiarity with EDR consoles (Microsoft Defender, CrowdStrike, SentinelOne); exposure to phishing analysis or identity-based attacks; and relevant certifications such as SC-200, CySA+, BTL1, or Security+.