Skip to main content

MSSP SOC analyst jobs: where to look and what to check

Find SOC roles at managed security providers, check current employer openings and compare shifts, location requirements, case ownership and training.

Updated by

JW
Jack WalshSep 29, 2026 · 9 min read

Hi, I'm Jack, the owner of Cybersecurity Jobs List, and co-founder of Himalayas (himalayas.app) and Cavuno (cavuno.com). Across all my platforms, I work with application security daily: dependency vulnerability scanning, secure authentication, API security, and data protection across hundreds of thousands of users. My technical background is in computer science (UNSW), where he studied security engineering and computer networks, and worked as a research assistant on VR experiments that were published in the Journal of Experimental Psychology. I also work with cybersecurity hiring data every day, tracking which companies are posting, what certifications actually appear in listings, how salaries differ by sub-discipline and clearance level, and where the talent gaps are widest. That combination of security practice, engineering at scale, and daily immersion in the hiring data is what shapes the content on this site. I'm currently based in Sydney, Australia.

Share this post

Illustration of a security analyst investigating signals from three customer organizations.
Conceptual illustration created for Cybersecurity Jobs List.

If you want a SOC job protecting several customers, start with the employers' own careers pages and search for both SOC analyst and security operations analyst. Then check where you can work, which shifts you would cover and how much investigation the role actually involves.

Below are three openings we checked, plus one employer board worth keeping on your shortlist. You can also browse SOC analyst jobs on Cybersecurity Jobs List if you want to compare provider roles with other security operations jobs.

An MSSP is a managed security service provider. MDR, or managed detection and response, describes a service focused on detecting, investigating and responding to threats. The terms overlap: an MSSP can deliver MDR. For a job search, look at the work and customers the team supports as well as the label the employer uses. Microsoft's MDR overview and MSSP documentation explain that relationship.

If you would rather work on defined client projects, explore our cybersecurity consulting company shortlist. It compares several types of consulting work and includes a worksheet for evaluating individual vacancies.

Four employer boards to start with

Employer sources checked 7 October 2026. “Opening checked” means the employer page displayed the role and an application form when we reviewed it. It does not guarantee the vacancy will remain open. “Watchlist” means a useful careers destination, not a confirmed current analyst vacancy. This is a starting list, not a ranking of employers.

EmployerStatus at our checkLocation or next check
VolexitySOC Analyst opening checkedRemote US and Australia; US West Coast preferred
HuntressSecurity Operations Analyst opening checkedRemote Australia; specified shift options
Arctic WolfCareers watchlistSearch the live board by role and location
BlueVoyantSOC Security Analyst L3 opening checkedRemote Philippines; Philippine citizenship required

Volexity: alert investigation and customer reporting

Volexity's SOC Analyst listing describes alert triage, threat hunting, detection tuning and reports for customers. It labels the role junior to mid-level, but asks for at least two years in an IT security focused role, with incident-investigation experience.

The location text names the US, with the West Coast preferred and other locations considered, and Australia. That wording is not a promise of worldwide remote eligibility. Confirm your location before investing time in the assessment.

The application asks for a completed skills assessment and an example of an incident report. Read those requirements early so you can plan your application. The page does not specify a shift pattern or closing date. Its emphasis on clear customer reporting makes this worth a look if you enjoy explaining what happened as much as finding the evidence. For future vacancies, use Volexity's careers page.

Huntress: intrusion response with stated Australian shifts

Huntress' Security Operations Analyst listing covers intrusion investigation, endpoint and log analysis, remediation advice and work with customer-facing teams. It asks for two or more years in SOC, incident response, MDR or digital forensics roles.

The role is remote within Australia. At our check, the shift choices were Western Australia, Monday to Friday, 8am–4pm AWST; or East Coast, Monday to Friday, 9am–5pm AEST or Tuesday to Friday, 8am–6pm AEST. Confirm which option is available to you and how daylight saving affects the roster. Those are the time-zone labels in the posting.

The form asks about Australian work authorization and sponsorship requirements; it does not establish that sponsorship is available. No closing date is stated. Start with the investigation requirements, then check whether the roster fits your life. Huntress' careers page is the broader route if this vacancy closes.

Arctic Wolf: watch the live board, not an old search result

Arctic Wolf describes separate triage and concierge security teams, with the triage team investigating alerts and supporting customers around the clock. That service structure makes it a relevant employer to follow, but it does not tell you an individual employee's schedule. Arctic Wolf's SOC overview explains the teams.

During our 30 September check, a Frankfurt triage analyst search result led to a removed job page. We have therefore kept Arctic Wolf as a watchlist entry rather than recommending that vacancy. Use its current careers board and search for triage, security operations or analyst roles in your location.

BlueVoyant: senior technical SOC work in the Philippines

BlueVoyant's SOC Security Analyst L3 listing describes complex investigations, technical escalations, client communication and mentoring junior analysts. Although the page labels the experience level “Mid Level,” the responsibilities call for a senior technical contributor.

The role is remote in the Philippines and explicitly requires Philippine citizenship. The application also asks whether you reside and are legally authorized to work there. Check those conditions before preparing an application.

The stated schedule is Sunday to Wednesday or Wednesday to Saturday, 7am–5pm. The posting does not name a time zone; confirm it with the employer. Five or more years of SOC, TOC or NOC experience appears under preferred qualifications, not as a stated minimum. The role still expects advanced investigation skills and a relevant degree or equivalent professional experience.

No closing date is stated. Use BlueVoyant's careers board for other openings if this role or its eligibility requirements do not fit.

Search beyond “SOC analyst”

A narrow title search can miss relevant work. Try these terms separately on employer boards:

  • Security operations analyst: look for investigation, alert triage and incident handling.
  • MDR analyst: check whether the role includes response, customer communication or both.
  • Triage analyst: read how much investigation happens before escalation.
  • Detection and response analyst: check the balance between live cases and building detections.

These are search suggestions, not interchangeable job titles. “Security analyst” can also describe work outside a SOC. A useful description tells you what you would investigate, which evidence you would use and who receives your findings.

For each promising role, separate required experience, preferred skills and unknowns. A tool you have not used is a different gap from a work-location restriction. If the employer's level labels are confusing, our SOC analyst tiers guide explains how to compare responsibilities across L1, L2 and L3.

Questions to ask before joining a provider SOC

The employer name gets you to a vacancy. The team details help you decide whether to take it. Use the questions below in an interview; they are prompts for gathering evidence, not assumptions about any company above.

What would my actual roster look like?

Ask for a sample roster covering a full rotation. Clarify nights, weekends, public holidays, on-call duties, time-zone changes and how much notice you receive before a shift changes. A service being available 24/7 does not mean every analyst rotates through every shift.

If compensation includes a shift allowance, ask which part is guaranteed and which depends on hours worked. Compare the offer in its own currency and pay period, alongside commuting costs and the schedule you can sustain.

How far would I take a case?

Ask the interviewer to walk through a typical alert: what the analyst can access, what they investigate, when they escalate and who can authorize containment. Find out whether you would speak to the customer directly or hand the case to another team.

For example, ask: “If I suspect an account takeover, who decides whether to disable the account, and what does my handoff need to contain?” You are looking for clear responsibilities, including the limits of your access.

Who reviews my investigations?

Ask who is available on your shift, how new analysts are supervised and whether closed cases receive feedback. “There is a senior team” leaves an important question unanswered: can you reach that team when you are working?

Ask how quality is assessed alongside speed. A concrete explanation of case review is more useful than a general promise of a supportive culture.

What does development look like during a busy week?

Ask for examples of how analysts get time for training, detection tuning or more complex investigations. Clarify whether learning time is part of the roster and how someone demonstrates readiness for additional responsibility.

You do not need a guaranteed promotion date. You do need to understand what you could learn and how the team would help you improve.

A shortlist worksheet you can copy

Use one copy per vacancy. Paste the source link and check date first; that gives you a way to spot changed requirements when you return.

Employer and role:

Official job link and date checked:

Location and work authorization: confirmed / needs clarification

Shift pattern and time zone:

Required experience I can demonstrate:

Preferred skills I would need to develop:

Typical investigation and escalation point:

Customer communication responsibilities:

Reviewer available during my shift:

Training time and evidence of progression:

Compensation and allowances, with currency and pay period:

Question I need answered before applying or accepting:

Next action: apply / clarify / watch for a better fit

Here is a fictional comparison to show how to use it. One provider offers a familiar tool stack, but has not explained overnight supervision. Another uses a tool you would need to learn, but describes paired investigations and a named reviewer during your shift. If your priority is developing investigation skills, the second deserves a closer conversation. That is a reason to ask better questions, not enough evidence to accept an offer.

An unknown should stay an unknown in your notes. Do not turn an attractive employer brand into an assumed answer about training, workload or flexibility.

Is an MSSP a good first SOC job?

It can be, if the specific role fits your experience and the team can support your learning. “Managed security provider” by itself does not establish either. The Volexity and Huntress openings ask for prior security experience, and the BlueVoyant role involves senior technical responsibilities. These examples should not be read as no-experience entry routes.

If you are moving from IT support, use our help desk to cybersecurity guide to identify relevant work you can already demonstrate. Be clear about what you did in employment and what you practiced in a lab. Neither a provider name nor an impressive project title replaces that distinction.

Choose one role where the location and core requirements fit. Tailor your application around a real investigation, a clear handoff or another relevant example you can explain honestly. Then use your shortlist questions to find out whether the team is a good place to do that work every day.

Related posts