Job Description
Role Summary
- We are seeking a SOC Analyst to monitor, investigate, and respond to cybersecurity threats across the organization’s IT environment.
- The analyst will work with SIEM, EDR, network security, and other security tools to identify suspicious activity, investigate incidents, and support timely remediation.
Key Responsibilities
- Monitor security alerts and events using SIEM platforms.
- Investigate and triage suspected security incidents.
- Analyze logs from endpoints, servers, firewalls, IDS/IPS, cloud environments, and applications.
- Perform alert correlation, threat analysis, and incident investigation.
- Identify indicators of compromise (IOCs), including malicious IPs, domains, hashes, and suspicious processes.
- Escalate confirmed or complex incidents to senior analysts or incident-response teams.
- Support incident response, containment, eradication, and recovery activities.
- Conduct basic threat hunting and identify suspicious patterns or anomalous behavior.
- Analyze phishing emails and investigate potentially compromised accounts.
- Document incidents, investigations, findings, and remediation actions.
- Maintain and improve security monitoring rules, detection logic, and dashboards.
- Assist with vulnerability management and security assessments where required.
- Stay informed about emerging threats, attack techniques, and MITRE ATT&CK techniques.
- Follow established security policies, procedures, and incident-response playbooks.
Key Performance Indicators
- Alert triage and response time
- False-positive reduction
- Incident detection and escalation accuracy
- Mean Time to Detect (MTTD)
- Mean Time to Respond (MTTR)
- Quality and completeness of investigation documentation
- Effectiveness of detection rules and threat-hunting activities.
Qualifications
- Degree or diploma in Cybersecurity, Computer Science, Information Technology, or a related field.
- Relevant certifications are an advantage, such as:
- CompTIA Security+
- CompTIA CySA+
- Blue Team Level 1 (BTL1)
- GIAC certifications
- Microsoft security certifications
- Splunk certifications
Typical Experience:
- Junior SOC Analyst: 0–2 years
- SOC Analyst: 2–4 years
- Senior SOC Analyst: 4+ years
Required Skills:
- Understanding of SOC operations and incident response.
- Knowledge of SIEM technologies such as Microsoft Sentinel, Splunk, QRadar, or Elastic.
- Experience with EDR/XDR platforms.
- Strong understanding of:
- TCP/IP and networking
- DNS, HTTP/HTTPS, SMTP
- Windows and Linux
- Active Directory
- Firewalls and IDS/IPS
- Authentication and access controls
- Ability to analyze security logs and correlate events.
- Knowledge of common attacks such as phishing, malware, credential theft, brute force, ransomware, and web attacks.
- Familiarity with MITRE ATT&CK, Cyber Kill Chain, and IOC analysis.
- Basic scripting knowledge, particularly PowerShell or Python, is advantageous.