Senior SOC Analyst

SUMMARY

DACTA is looking for a highly motivated and experienced Senior SOC Analyst to join our Security Operations Centre (SOC) team. The Senior SOC Analyst will be responsible for monitoring, investigating, analysing, and responding to complex security incidents across various security platforms and technologies, while also managing and leading a small team of SOC Analysts.

The role involves advanced security investigations, incident response, threat hunting, security event analysis, and continuous improvement of security monitoring capabilities. The successful candidate will provide technical guidance and support to the SOC team, ensure effective day-to-day operations, and work closely with cybersecurity, IT, network, infrastructure, and other technical teams to identify, contain, and remediate security threats.

RESPONSIBILITIES

  • Continuously monitor and analyse security events and alerts from various sources, including SIEM, EDR/XDR, firewalls, IDS/IPS, endpoint security, network security, and other security infrastructure.
  • Investigate and respond to security incidents, including complex and high-severity cybersecurity events.
  • Conduct detailed analysis of security events, logs, network traffic, endpoint activities, and other relevant security data to determine the severity, impact, scope, and root cause of incidents.
  • Perform advanced incident investigation and determine appropriate containment, eradication, recovery, and remediation actions.
  • Conduct threat hunting activities to proactively identify suspicious activities, indicators of compromise (IOCs), attacker behaviours, and potential security threats.
  • Develop and utilize threat-hunting queries and techniques to identify emerging threats and malicious activities.
  • Analyse and correlate information from multiple security sources to identify attack patterns, anomalies, and potential security incidents.
  • Perform analysis of malware, suspicious files, URLs, domains, IP addresses, and other indicators of compromise where required.
  • Analyse threat intelligence and security research to identify emerging cybersecurity threats, vulnerabilities, attack techniques, and indicators that may affect the organisation or its customers.
  • Apply recognised cybersecurity frameworks and methodologies, including MITRE ATT&CK, during security investigations and threat analysis.
  • Develop, maintain, and improve SIEM correlation rules, detection rules, dashboards, alerts, and security monitoring use cases.
  • Assist in tuning and optimizing security tools and detection mechanisms to improve detection accuracy, reduce false positives, and enhance overall SOC capabilities.
  • Identify gaps in existing security monitoring and recommend improvements to security tools, processes, procedures, and detection capabilities.
  • Coordinate with IT, network, infrastructure, application, and other technical teams to facilitate timely investigation, containment, and remediation of security incidents.
  • Participate in the management and response of major or critical security incidents and provide technical recommendations to relevant stakeholders.
  • Conduct root cause analysis and post-incident reviews and provide recommendations to prevent recurrence of security incidents.
  • Prepare and maintain detailed incident reports, investigation findings, root cause analysis, remediation recommendations, and other security documentation.
  • Develop and maintain incident response procedures, playbooks, investigation guides, and SOC operational documentation.
  • Provide technical guidance and knowledge sharing to SOC team members to improve investigation and incident-handling capabilities.
  • Participate in regular SOC meetings, cybersecurity training, tabletop exercises, knowledge-sharing sessions, and continuous improvement initiatives.
  • Maintain up-to-date knowledge of cybersecurity threats, vulnerabilities, attack techniques, security technologies, and industry best practices.
  • Perform other cybersecurity and SOC-related duties and responsibilities as assigned by management.
  • Manage and lead a small team of SOC Analysts to ensure effective day-to-day SOC operations and timely handling of security incidents.

REQUIREMENTS

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Security, or a related field, or equivalent professional experience.
  • 5 years or more of relevant experience in SOC operations, cybersecurity, security monitoring, incident response, or a related cybersecurity environment.
  • Strong hands-on experience in security monitoring, incident investigation, and incident response.
  • Strong experience with SIEM platforms, such as Splunk, ArcSight, QRadar, Microsoft Sentinel, or similar technologies.
  • Experience with EDR/XDR, IDS/IPS, firewalls, endpoint security, network security, and other cybersecurity technologies.
  • Strong understanding of networking protocols and concepts, including TCP/IP, DNS, HTTP/HTTPS, SMTP, VPN, routing, and network traffic analysis.
  • Strong knowledge of Windows and Linux operating systems, including system logs, processes, services, authentication mechanisms, and common security events.
  • Strong understanding of common cybersecurity attack vectors and techniques, including malware, phishing, credential compromise, privilege escalation, lateral movement, command and control, data exfiltration, DDoS, and Advanced Persistent Threats (APTs).
  • Good knowledge of MITRE ATT&CK and other recognised cybersecurity frameworks and methodologies.
  • Experience in threat hunting, IOC analysis, log analysis, event correlation, security investigation, and root cause analysis.
  • Experience in developing, tuning, or optimizing SIEM correlation rules, detection rules, alerts, dashboards, and security use cases would be an advantage.
  • Knowledge of incident response methodologies and security incident lifecycle management.
  • Strong analytical, critical-thinking, and problem-solving skills with excellent attention to detail.
  • Good written and verbal communication skills, with the ability to clearly document and communicate technical findings.
  • Ability to independently manage multiple security incidents and prioritize tasks according to severity and business impact.
  • Strong teamwork and collaboration skills, with the ability to work effectively with cybersecurity, IT, network, infrastructure, and other technical teams.
  • Ability to work effectively in a fast-paced.
  • Relevant cybersecurity certifications such as Security+, CySA+, GCIH, GCIA, CEH, or equivalent would be an advantage.

See also

Data Analytics jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available