The SOC Analyst is accountable for detecting security incidents in the SOC and translating security impacts to the wider business S He monitors the security control reviews the incident tickets and leverages emerging threat intelligence to identify affected systems and scope of attack
Main Duties and Responsibilities
- Participate in the gathering analysis and communication of threat intelligence through the intelligence process lifecycle
- Apply technical skills to analyze files and related components using tools and technologies
- Perform in-depth analysis of incidents created from L1 team
- Understand the underlying behavior and implication on a computer and network environment
- Respond to customer queries and concerns within a given timeline to address related concerns
- Determine and direct remediation and recovery efforts
- Understand vulnerability scans and review vulnerability assessment reports
- Manage configure and improve security monitoring tools SIEM among others as per client needs
- Promote a professional image of the company and the professional services function at all times
Position Requirements
- At least one security certificate CEH OSCP CISSP CCNP Sec etc
- Any CCNP Cisco Certified Network Professional or equivalent
- Any non-vendor security certificate CISSP CISM ISO27001 GCIA GCIH GCFA GCFE etc
- Understanding of log formats LEEF CIF and protocols syslog ftp logfie
- Knowledge of security devices such as IDS IPS HIDS HIPS anomaly detection Firewall and Antivirus systems and their log output
- Network forensics network traffic protocols traffic analysis i e Network flows and PCAP
- Working knowledge of SIEM tools such as RSA ArcSight Splunk and QRadar and etc
- EducationBachelor s degree in Computer Science or any other related field
- ExperienceAt least 2 years of relevant experience