Job Description
Collaborate to run and improve the SOC: defining processes, collecting and deploying tools, and providing technical training to internal employees
Monitor and triage security alerts from EDR, SIEM, and cloud platforms (mainly M365, Entra ID, Azure)
Continuously design, amend and improve playbooks, SOPs and detection use cases in SIEM
Analyze logs across endpoints, cloud services, and applications to determine root cause, impact, and scope of incidents
Execute containment, remediation, and recovery actions following established incident response procedures
Escalate and coordinate security event analysis with external partners / vendors
Actively monitor IT / OT security monitoring tools, perform vulnerability testing and threat hunting, and assist with malware and patch management
Follow current developments in the threat landscape, analyze security news feeds and initiate appropriate clarifications and defensive measures
Contribute to automation initiatives for alert enrichment, workflow optimization, and incident response processes
Report periodic KPI’s about security issues (may provide evidence of a cyberattack to act against the individuals for breaching security)
Collaborate with engineering, IT, and business teams during investigations and incident response activities
Track and report key operational metrics including incident trends, response times, and alert quality
Area of Responsibility
Responsibility for SOC processes on detection and response, cyber security incidents, and vulnerability management for the company's internal IT environment. Acts according to instructions given to respond within the expected meantime to response
Work Experience
Minimum 3-5 years of experience in security operations / analyst positions.
Experience working in large corporate environments and using different security tools (AV, EDR, SIEM, NDR/IDS, SOAR, proxies, firewalls, etc.)
Experience in troubleshooting medium to complex security issues and has ability to analyze the environment for vulnerabilities (SOC Level 1 and 2 tasks)
Knowledge in critical security controls, EDR (Endpoint Detection and Response), NDR (Network Detection and Response) and malware analysis
Knowledge of operating systems and network protocols
Worked on security events and incident management
Preferably knowledge in scripting (PowerShell, Python, etc.)
Qualifications
Education Required
Bachelor of Engineering or Bachelor of Technology or any equivalent degree in science & technology Branch.
IT Security education and/or certifications are of advantage
Areas of ExpertiseHandling and troubleshooting security events and incidents, preferably within SIEM
Knowledge and collaboration with client / server / network SME’s
Managing and working with antivirus at an enterprise level (Sophos)
Knowledge in TCP/IP protocols and web application technology
Knowledge of Azure and Office 365 services
Working experience with ITSM tools and processes
Ability to perform root cause analysis on the problem/issues published and find the appropriate solution
Ability to lead and handle the tasks independently
Knowledge in scripting, preferably PowerShell
Regards
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
