Description and Requirements
Job Description
Security Operations Centre (SOC) Analyst plays a vital role in Security delivery. As a SOC Analyst, you will be on the front line of Cyber Defense, detecting & responding to Cyber Incidents as they happen. You will work with other team members to provide situational awareness through detection, containment, and remediation of IT threats. This job requires great attention to detail and general awareness of Cyber Security tools like SIEM, XDR, EDR, IDS / IPS, ability understand various logs – network logs, sys logs, Firewall logs. As a SOC Analyst you are expected to have working knowledge in areas of networking, malware analysis, incident response, vulnerability management.
Responsibilities
As a SOC Analyst – Level 1, you will :
Monitor security logs and alerts from different security monitoring platforms and sources using SIEM and direct information on an advanced level
Perform Triage on Incidents detected.
Submit incidents for a follow-up to functional maintenance.
Track progress on incidents that have been submitted from outside of the SOC
Resolve Incidents as per Standard Operating Procedure (SOP)
Propose and identify automation opportunities resulting from incidents.
Prepare SOC Management Reports.
Analyzing & preparing daily and monthly reports based on the devices which are being monitored
Creating Reports and Dashboards based on the customer requirement.
Creating Reports which helps in providing the logs for the alerts, for finding any possible threats.
Analyze a variety of network and host-based security appliance logs (Firewalls, NIDS, HIDS, Sys Logs, etc.) to determine the correct remediation actions and escalation paths.
Work under supervision of technical lead to accomplish assigned tasks.
Change Management / Implementation : Independently implement changes to meet customer infrastructure needs within area of technical responsibility
Patch and Security Management : Apply patch and security changes per policy."
Configuration Management : Ensure Configuration Management Database (CMDB) entries are complete and accurate.
Quality : Provide continual improvement recommendations for direct responsibility area (process improvement, technical standard updates, etc).
Project Management : Participate in customer and internal projects, including transformation.
Customer Relationship Management : Set expectations with customers and / or internal businesses / end users within defined parameters.
Teamwork : Work as part of a team, which may be virtual and / or global. Participate as part of a team and maintains good relationships with team members and customers
Skill
2-4 years of relevant experience
Typical skills include :
Sufficient depth and breadth of technical knowledge to be individually responsible for the implementation of a specific deliverable.
Understanding of technology in direct responsibility (SIEM, XDR, EDR, MDR)
General understanding of related technologies (Networking, Operating Systems)
Customer Service
General Project Management (Basic)
Customer / Vendor Management (Basic)
Able to communicate broad and specific concepts with team and to peers.
Able to produce documentation for use by team and customer.
Good verbal & written communication skills
Proactive approach to meet & exceed goals
Qualification & Experience
Bachelor’s Degree in Engineering, Computer Science
2 – 4 years of relevant experience in SOC domain
Understanding of ITIL process
Security related certifications (Security+, CEH) will be an added advantage
Additional Locations :
Cyber Security Engineer • bangalore, India