
SOC Cyber Security Specialist
ON2IT
Job description
Our customers trust us to keep their networks out of the news. You are the person who makes that true.
You analyze what is really happening on a customer’s network, decide what matters, and configure the controls that stop the next attempt. You work on-site in Plano, TX, part of our global Security Operations Center (GSOC) team.
What you will do
• Analyze - anomalies, alerts and threats, and decide what is real
• Fix - security issues in routing and networks
• Configure - security controls along Zero Trust principles
• Work hands-on - with protocols like SSH, SSL, HTTPS, SMTP and DHCP, and whatever else the customer runs
• Document - your work so the colleague taking over hits the ground running
How we work with AI
We invest in AI for two reasons: it keeps us ahead of innovation, and it keeps pace with how fast modern threats change. AI is built into our service, not bolted on. MDR Detect™ runs AI-assisted case handling behind our human-led GSOC, and we build our own AI infrastructure, shaped by the specialists who use it. That could be you. No problem if you are not an expert yet. Curious and honest about the gaps? Essential.
What we offer
• A clear path - Junior to Medior to Senior, with explicit criteria for each step
• Cutting-edge technology - new environments and concepts every day, for customers all over the world
• Unlimited learning - training, certification, education, and the time to do it
ON2IT Inc. is an equal opportunity employer. We evaluate every applicant on qualifications and merit, regardless of race, color, religion, sex, national origin, age, disability, veteran status, or any other status protected by law.
And it matters. Our customers are hospitals, research labs, retailers, banks and manufacturers. When you catch something early, their operation keeps running and the people who depend on it never notice anything happened. That is the point of the job.
Requirements
Who you are
• You pull the thread - until you understand it, and you say “I don’t know yet” instead of guessing
• You own it - a customer’s request stays yours until it is solved
• You read the organization - not just the network
• You convince with insight - not volume, and you explain without making anyone feel stupid
Experience
• Relevant experience - 2-3 years of experience in a SOC, NOC, or similar security-operations role
Technical foundation
• Networking - routers, switches, firewalls (CCNA level, or heading there)
• Concepts - network segmentation, VPN, NAT, DNS and certificates
• Security thinking - least privilege, defense in depth, and how an attack moves once it is inside
• Systems - Windows, macOS and Linux
• Protocols - the common ones (SSH, SSL, HTTPS, SMTP, DHCP) and the confidence to pick up the rest
• Certifications - a relevant certification (for example CCNA or Security+) or actively working toward one; we sponsor further certification
AI and modern tooling
• You use AI daily - and can explain how, not just that you do
• You get prompting - context and structure, not incantations
• You spot repetition - and package it into something reusable
• You respect confidentiality - customer data does not go just anywhere
• You can use git - clone, branch, commit, open a merge request
• You can write Markdown - our runbooks and AI context live in plain text
The rest
• English - excellent, spoken and written
• On-site - required. This is not a hybrid role, and you live within commuting distance of our Plano, TX office
• Screening - due to the sensitive nature of the job, every hire goes through pre-employment screening
Nice to have
• Product experience - Palo Alto Networks Strata or Cortex, Microsoft Defender, Fortinet FortiGate or similar
• Background - SOC, NOC or managed services experience
• Certifications - Palo Alto Networks Security Operations Professional, Palo Alto Networks Network Security Professional, CompTIA Security+, or Microsoft Security Operations Analyst
• Scripting - Python, Bash or similar