SOC Analyst
Summary
The SOC Analyst monitors, detects, and responds to security incidents by analyzing alerts from SIEMs and other security infrastructure. The role involves triaging threats, documenting findings, and collaborating with IT teams to mitigate risks in a 12-hour shift environment.
Our Company is growing rapidly, and we are looking forhighly motivated individuals to work in a SOC environment leveraging SIEMs andsecurity tools to assist in detecting potential security threats. The SOCanalyst role is to monitor, detect and respond to security incidents. The roleinvolves triaging, analyzing alerts, determining the criticality of theincidents, and escalating them accordingly.
RESPONSIBILITIES
- Continuously monitor securityalerts from various sources such as firewalls, intrusion detection/preventionsystems (IDS/IPS), Security Information and Event Management (SIEM) tools, andother security infrastructure.
- Respond to and investigatesecurity incidents.
- Collaborate with senior SOCanalyst on complex incidents and provide appropriate recommendation forremediation.
- Escalate incidents andconcerns to higher-tier analysts or specialized security teams whennecessary.
- Conduct detailed analysis ofsecurity events, logs, and alerts to determine the severity and root cause ofincidents.
- Provide and maintain detailedrecords of incidents, actions taken, and outcomes for internal tracking andpost-incident analysis.
- Gather and analyze threatintelligence to stay up to date on emerging cybersecurity risks andvulnerabilities.
- Collaborate with IT, network,and infrastructure teams to ensure appropriate measures are taken to prevent ormitigate future incidents.
- Assist in the tuning andoptimization of security tools, systems, and processes to improve detectioncapabilities.
- Participate in regular teammeetings, training sessions, and knowledge-sharing activities to improve teamperformance and security posture.
- REQUIREMENTS/EDUCATION
- Diploma or Bachelor’sdegree in Cybersecurity, Information Technology, or related field, orequivalent work experience.
- Strong understanding ofnetworking protocols and concepts (TCP/IP, DNS, HTTP/S, etc.).
- Experience with SIEMplatforms (e.g., Splunk, ArcSight, QRadar, or similar tools) would bepreferable.
- Ability to investigate andanalyze security incidents with attention to detail.
- Good communication skillsfor documenting and reporting incidents.
- Ability to work in afast-paced, high-pressure environment.
- Knowledge of common attackvectors, including but not limited to malware, phishing, DDoS, and APTs(Advanced Persistent Threats).
- Knowledge in various cyberdefense methodology and frameworks(i,e Mitre ATT&CK, etc)
- Familiarity with operatingsystems (Windows, Linux) and networking devices (routers, switches,firewalls).
- Critical thinking andproblem-solving abilities.
- Ability to prioritize andmanage multiple tasks effectively.
- Strong teamwork andcollaboration skills.
- Working hours: The working hours will change as we grow. Currentlywe are looking for individuals who are able to work on 12-hour shift.