POSITION SUMMARY:
The SOC L1 Analyst Intern is an entry-level developmental position within Aspire Technology Partners’ Security Operations Center (SOC). Working under the direction and supervision of experienced SOC analysts, the Intern will learn to use a variety of security tools to monitor, triage, investigate, document, and escalate security-related alerts for Aspire’s Managed Services Clients. The position is designed to build the foundational technical, analytical, customer service, and operational skills required for progression into a SOC Analyst Level 1 role. Training and hands-on experience may include SIEM alert review, incident triage, correlation of data from firewall, endpoint security, SASE, DNS, network and IPS logs, use of runbooks and playbooks, case documentation, and escalation procedures. Interns are expected to demonstrate continuous learning, sound judgment, attention to detail, and adherence to established SOC procedures while working within the scope of their training and assigned responsibilities.
ESSENTIAL DUTIES AND RESPONSIBILITIES- MAY INCLUDE THE FOLLOWING: OTHER DUTIES MAY BE ASSIGNED.
Participate in the SOC Intern training program and complete assigned technical, operational, and customer-service training activities.
- Monitor and triage security alerts under the supervision of SOC Analysts and follow established runbooks, playbooks, Standard Operating Procedures, and escalation paths.
- Assist with analysis of security events and document a clear narrative supporting observations, actions taken, and escalation decisions.
- Create, update, track, and close SOC cases/tickets in accordance with established procedures and Service Level Agreements (SLAs), as authorized.
- Learn to correlate security telemetry from SIEM, firewall, endpoint security, SASE, DNS, network traffic, IPS, and other supported security platforms.
- Create and run approved search queries in SIEM and security tools to assist with identifying and troubleshooting security issues.
- Research current security vulnerabilities, attacks, threat actors, security advisories, Indicators of Compromise (IOCs), phishing techniques, and the MITRE ATT&CK Framework.
- Assist with investigation of malware, phishing, endpoint, account, network, and other security events within the scope of assigned training.
- Escalate suspected or confirmed security incidents to Level 1, Level 2, Senior Analysts, Incident Responders, or SOC leadership in accordance with SOC procedures.
- Maintain accurate and detailed notes of security events, investigations, customer communications, and actions taken within approved operational systems.
- Observe and assist with customer communications, hotline calls, email, and meetings as assigned and under appropriate supervision.
- Work collaboratively with SOC Level 1 and Level 2 Analysts, Senior Analysts, Incident Responders, SOC Engineering/DevOps, and NOC resources as appropriate.
- Assist with SOC reports, knowledge-base articles, research, documentation, and other assigned continuous-improvement activities.
- Develop proficiency with the security technologies and processes required for progression toward a SOC Analyst Level 1 position.
- Demonstrate ownership of assigned training tasks, meet established training milestones, and seek guidance when an issue exceeds current knowledge or authorization.
- Obtain or work toward technical/professional certifications applicable to the position or as directed.
- Perform other duties as assigned.
Minimum Education and Experience:
- High School Diploma or equivalent, or currently enrolled in an accredited high school, college, university, technical, or cybersecurity training program as permitted by company policy
- Foundational knowledge of computer systems, networking, cybersecurity concepts, or information technology
- Interest in developing a career in cybersecurity and Security Operations
- Ability to learn and follow Runbooks, Playbooks, Standard Operating Procedures, documentation standards, and escalation processes
- No prior professional SOC experience required
Preferred Education and Experience:
- Coursework, degree program, or technical training in Cybersecurity, Information Technology, Computer Science, Networking, or a related field
- Exposure to SIEM, endpoint security, firewalls, DNS security, network traffic analysis, or ticket/case management tools
- Familiarity with common security concepts including phishing, malware, Indicators of Compromise (IOCs), Endpoint Detection and Response (EDR), and the MITRE ATT&CK Framework
- Cybersecurity labs, internships, help desk, NOC/SOC, CTF, home lab, or other hands-on technical experience
- Industry certification or active pursuit of a certification such as Security+, CySA+, Cisco CyberOps Associate, or similar
OTHER SKILLS and ABILITIES:
- Excellent Interpersonal Skills (develop and maintain strong working relationships)
- Displays ownership of tasks
- Detail oriented with strong written and verbal communication skills.
- Ability to prioritize tasks.
- Strong organizational skills
- Ability to work an assigned SOC schedule and participate in after-hours or weekend activities when required and appropriate for the Intern role.
- Basic telephone operation skills
- Excellent customer service skills
- Familiarity with ITIL Processes
- Proficiency in Microsoft Office programs and ability to learn specialized system tools
- Ability to multi-task in a fast-paced environment
TRAVEL: (Limited to No Travel)
PHYSICAL DEMANDS: The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
While performing the duties of this job, the employee is regularly required to sit and talk or hear. The employee frequently is required to stand; walk; and use hands to finger, handle, or feel objects, tools, or controls. The employee is occasionally required to reach with hands and arms. The employee must occasionally lift and/or move up to 35 pounds. Specific vision abilities required by this job involve normal vision.
WORK ENVIRONMENT:
In Office
Employees located within one hour and thirty minutes of our main location will be expected to come into the office 5 days per week. Temporary remote work is possible if authorized by your manager.
The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
The noise level in the work environment is usually quiet to moderate.
Remote
Anyone over one hour and thirty minutes from our main location can work remotely. Necessary equipment to perform your job functions will be sent to your address. All equipment will be tracked in our inventory system and will be expected to be returned in the same condition as when it arrived at the conclusion of any employment agreement. You may be asked to visit client or remote sites if necessary.