Rapid7's SOC team is responsible for our APAC customers as part of our global 24/7 managed services. As an experienced SOC analyst, you will have the opportunity to impact this team, work alongside Incident Response Consultants, and mentor others while advancing your career with a globally recognized cyber security company.
About the Team
Rapid7 Managed Detection and Response (MDR) is built from the ground up to bring motivated and passionate security talent face to face with emerging threats, practical challenges, and evil at scale.
Our MDR service uses an impact-driven mindset to focus efforts on effective solutions, encouraging personal and technical innovation within the SOC. MDR provides 24/7/365 monitoring, threat hunting, incident response, and more with a focus on endpoint detection and behavioral intelligence.
About the Role
As a SOC Analyst, your primary responsibility will be to identify, analyze, and lead investigations into malicious activity across customer environments scaling in complexity from commodity malware to zero-day vulnerabilities and sophisticated threat actors. You will be empowered to steer end-to-end investigations, including evidence acquisition, forensic analysis, root-cause identification, and customer remediation. Specifically, your focus will be to:
- Deliver world-class threat detection services utilizing Rapid7 software, traditional threat intelligence, and user behavior analytics to identify potential compromises across customer infrastructure.
- Conduct or lead Rapid7 incident response investigations on workstations, servers, and cloud environments, steering evidence acquisition, forensic analysis, malware analysis, and root-cause analysis.
- Write detailed technical findings and Incident Reports aligned with the MITRE ATT&CK Framework, documenting technical analysis, malware behaviors, and actionable remediation recommendations for customers.
- Communicate effectively with Customer Advisors on client Requests For Information (RFIs), complex technical concepts, and investigation findings.
- Collaborate with fellow analysts to share intelligence regarding threat actor tactics, techniques, and trends (TTPs), elevating team capability.
- Provide continuous input and operational feedback to Threat Intelligence, Detection Engineering, and product development teams to identify new detection opportunities.
- Support customer engagement opportunities regarding MDR service functions when necessary.
The skills and qualities you'll bring include
- Bring 3 - 4 years of experience in a cybersecurity-related position, with dedicated SOC or SIEM analysis experience preferred.
- Demonstrate strong knowledge of Windows, Linux, and MacOS operating systems alongside core security concepts and threat actor tactics (e.g., lateral movement, privilege escalation, defense evasion, persistence, exfiltration, and command and control).
- Show practical hands-on experience participating in cybersecurity challenges (such as CTFs, HTB, Rastalabs) or utilizing penetration testing tools (like Mimikatz, Metasploit, or BloodHound).
- Apply hands-on experience with analyzing forensic artifacts and malware samples to uncover threat actor activity.
- Utilize scripting and coding ability to automate tasks, analyze forensic data, and solve complex technical problems.
- Bring a creative approach to critical problem-solving with analytical decision-making when triaging security events and identifying root causes during active investigations.
- Prioritize customer success by putting client needs at the forefront of technical recommendations, investigative reporting, and customer remediation guidance.
- Hold yourself and others responsible for driving outcomes, taking ownership of incident investigations, and meeting commitments that deliver value for the business and our customers.
- Make efficient, clear decisions that resolve challenges and enable momentum, integrating diverse perspectives and ensuring transparency in the process.
- Navigate change and ambiguity eagerly as threat actor TTPs, vulnerabilities, and security technologies continuously evolve, acting as an active driver of continuous improvement.
- Communicate in a clear manner that conveys objectives and complex technical concepts, fostering commitment and cross-functional collaboration between the SOC, Threat Intelligence, and Customer Advisory teams.
- Embody our core values to foster a culture of excellence that drives meaningful impact and collective success.
We know that the best ideas and solutions come from multi-dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don't be shy - apply today.
#LI-PB1
About Rapid7
At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome.
Protecting 11,500+ customers against bad actors and threats means we're continuing to push the envelope just like we' ve been doing for the past 20 years. If you 're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us.
Skills Required
- 3–4 years of experience in a cybersecurity-related position
- Knowledge of Windows, Linux, and macOS operating systems, security concepts, and threat actor tactics
- Hands-on experience with cybersecurity challenges such as CTFs, Hack The Box, or Rastalabs, or penetration testing tools such as Mimikatz, Metasploit, or BloodHound
- Hands-on experience analyzing forensic artifacts and malware samples
- Scripting and coding ability to automate tasks and analyze forensic data
- Dedicated SOC or SIEM analysis experience
- Strong analytical decision-making and complex technical problem-solving skills
- Clear communication of complex technical concepts and investigation findings
- Customer-focused approach to technical recommendations, reporting, and remediation guidance
What We Do
At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what’s possible and drive extraordinary impact. We’re building a dynamic and collaborative workplace where new ideas are welcome. Protecting 11,000+ customers against bad actors and threats means we’re continuing to push the envelope - just like we’ve been doing for the past 20 years. If you’re ready to solve some of the toughest challenges in cybersecurity, we’re ready to help you take command of your career. Join us.
Why Work With Us
With our products, research, and open source communities, we’re building a secure digital future for everyone. This means constantly learning and evolving in an industry that’s anything but stagnant. You’ll be faced with tough challenges, and given the support to find creative solutions that drive our business, and your career forward.
Gallery
Rapid7 Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
Our default working model is hybrid, with employees working three days per week in the office. This approach underpins our commitment to flexibility and adaptability while supporting our dedication to development, teamwork and customer purpose.

.jpg)



















.jpg)
























