Senior SOC Analyst
Summary
Senior SOC Analyst at Worldline protects IT systems by triaging, investigating, and responding to security alerts and incidents using SIEM, EDR, and SOAR tools in a hybrid role based in Bucharest.
The opportunity
Join the Cyber Defense Center (CDC) division which is in charge of protecting Worldline IT systems, workstations and production assets, against Cyber Threats.
Within the Security Operations Center (SOC) and in close collaboration with the other teams that make up the CDC, namely Incident Response - Cyber Threat Intelligence - Assessments - Vulnerabilities Operations Center - Engineering - Continuous Improvement, we would like you to contribute to the delivery and ongoing development of our core services which are triage, investigation and response to security alerts and incidents.
As senior Security Analyst, you will also be expected to support your teammates and to help them grow, while continuously improving the industrialization, automation, efficiency and quality of our SOC services.
Day-to-day responsibilities
- Be part of an international team processing security alerts and incidents.
- Perform complex and in-depth analysis using the available technologies and tools, leveraging your experience and knowledge.
- Writing down procedures, work instructions and incident reports.
- Support and train the security analysts of the SOC.
- Contribute to quality checks of our SOC services deliveries.
- Propose improvements to the existing use-cases and alerts based on your observations.
- Suggest new use-cases and alerts based on your observations.
- Identify and suggest opportunities to improve our SOC detection and response capabilities.
- International collaboration with the other CDC teams, especially those responsible fo Cyber Threat Intelligence, Incident Response and Engineering.
Who are we looking for
We look for big thinkers. People who can drive positive change, step up and show what’s next – people with passion, can-do attitude and a hunger to learn and grow. In practice this means:
- 4 years+ of experience in similar role as part of a SOC or equivalent.
- Familiarity with SIEM (preferably Splunk), EDR (preferably MS Defender / SentinelOne) and SOAR (preferably SwimLane).
- Understanding the methods and tactics used by the Threat Actors.
- Knowledge of security frameworks like MITRE Att&ck and Cyber Kill Chain.
- Knowledge of OS (Windows / Linux), Network Technologies (VPN, FW, GW, Proxies) and Applications Security.
- Strong team spirit and excellent communication skills.
- Rigorous approach to work, organization, structured and analytical mindset, strong commitment, and eagerness to learn.
- Academic degree in Information Technology or Security (Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field). Security Certification (e.g. CEH) would be an advantage.
- Fluency in spoken and written English is mandatory as we are international teams.
Perks & Benefits
- Hybrid Working Policy
- Gift vouchers on the occasion of Christmas/Easter Holidays
- Private medical services
- 21 vacation days/year
- Referral bonuses for new hires recommended by you
- WFH & Flexible Working Hours
- Full access to the “Learning” platform