Security Operations Center (SOC) Analyst
Duration: 6 months
Location: Houston, TX
Schedule: Monday - Friday: 7am - 4pm
Role Summary
The SOC Analyst is responsible for monitoring, investigating, documenting, and coordinating response to cybersecurity events across enterprise environments. This role is designed for an analyst with 3?5 years of hands-on experience in SOC operations, incident response, phishing investigation, threat monitoring, or related cybersecurity operations. The analyst is expected to communicate clearly, collaborate early with senior cybersecurity personnel and cross-functional teams, and exercise sound judgment during complex or time-sensitive investigations.
Essential Functions and Responsibilities
- Monitor, triage, validate, and investigate security alerts from SIEM, EDR, email security, identity, network, cloud, and other cybersecurity platforms.
- Analyze suspicious activity, indicators of compromise, malware alerts, account compromise indicators, unauthorized access attempts, phishing emails, smishing messages, malicious links, and business email compromise attempts.
- Document investigation findings, actions taken, supporting evidence, recommendations, and response activities in designated ticketing or case management systems.
- Coordinate with senior cybersecurity personnel, IT, OT, email administrators, endpoint teams, identity teams, business stakeholders, and affected users to support investigation, containment, remediation, and user guidance.
- Participate in incident response activities, including evidence gathering, timeline development, stakeholder coordination, lessons learned, and post-incident improvement efforts.
- Review threat intelligence, vulnerability disclosures, and security advisories to identify relevant indicators, attacker techniques, and potential impacts to the organization.
- Conduct proactive threat hunting and recommend detection improvements, correlation rules, alert tuning, and workflow enhancements.
- Support security control validation, cybersecurity awareness activities, phishing simulations, vulnerability prioritization, operational reporting, and metrics development.
- Maintain and improve SOC playbooks, standard operating procedures, investigation templates, knowledge articles, and analyst handoff practices.
- Communicate investigation status, risk, findings, and recommended next steps clearly to technical teams, senior team members, business stakeholders, and end users.
Preferred Qualifications
- Industry certification such as CompTIA Security+, CompTIA CySA+, Microsoft SC-200, Cisco CyberOps Associate, GSEC, GCIH, CEH, or similar cybersecurity certification.
- Experience writing or modifying SIEM queries, EDR detection logic, threat hunting queries, or basic automation scripts.
- Knowledge of MITRE ATT&CK, Cyber Kill Chain, NIST incident response concepts, or similar threat and response frameworks.
- Experience supporting cybersecurity awareness programs, phishing simulations, vulnerability prioritization, remediation tracking, control validation, reporting, or exposure management activities.
- Interest in mentoring junior analysts, improving SOC processes, and contributing to a collaborative, team-oriented security operations culture.
Knowledge, Skills, and Abilities
- Strong understanding of SOC workflows, incident response concepts, threat intelligence, vulnerability management, and security monitoring fundamentals.
- Ability to recognize phishing, smishing, business email compromise, malware activity, credential compromise, suspicious user behavior, and common attacker tactics.
- Strong technical analysis, documentation, prioritization, problem-solving, and customer service skills.
- Ability to clearly communicate findings, risks, investigation status, and recommended next steps to both technical and non-technical audiences.
- Ability to collaborate effectively with senior analysts, incident responders, IT, OT, infrastructure, identity, email, endpoint, and business teams.
- Commitment to continuous learning, adaptability, and improving SOC processes, detections, and response workflows.
- Active TWIC card
Work Environment and Physical Demands
This role operates in a professional office environment within or outside of an industrial plant environment and routinely uses standard office equipment. The role is primarily sedentary; however, the incumbent must be able to sit and/or stand for a full shift, lift up to 20 lbs. as needed, move throughout office or site locations, and drive to other Company work locations as required.
Other Duties
This job description is not intended to contain a comprehensive listing of all activities, duties, or responsibilities required of the employee. Duties, responsibilities, and activities may change at any time with or without notice.
HSE Roles and Responsibilities
Support the policies, efforts, and programs of the Freeport LNG Health, Safety and Environmental (HSE) Management System. Actively participate in HSE Management System policies and ensure HSE concerns are prioritized in all activities completed within the incumbent?s area of responsibility.
#LI-BF2