About This Job
Lintasarta
Location: Jakarta, Indonesia
Work Mode: On-site
Industry: Technology, Information and Media, IT Services and IT Consulting
Job Description
We are Hiring: Splunk Security Analyst (SOC Hybrid Tier 1/2)
Are you a vigilant cyber defender who knows how to navigate Splunk like the back of your hand? We are looking for a Splunk Security Analyst to join our fast-paced, 24/7/365 Security Operations Center (SOC) team!
In this hybrid role, you will be our frontline defender and core investigator. You will be responsible for real-time security alert monitoring and initial triage, while also taking ownership of escalated alerts to perform deep-dive technical investigations, confirm malicious intent, and drive active containment strategies using the Splunk platform.
Key Responsibilities
- Real-Time Monitoring, Triage & Escalation
- Continuously monitor security alerts generated across enterprise SIEM (Splunk), EDR, and cloud logging solutions to identify potential malicious activities.
- Review and triage security events to accurately differentiate between true security threats and false positives based on established playbooks.
- Document highly detailed, clear, and comprehensive incident tickets logging the timeline, systems involved, and Indicators of Compromise (IoCs).
- Execute thorough shift handovers to ensure uninterrupted 24/7/365 operational coverage.
- Deep-Dive Investigation & Response
- Investigate complex security alerts by correlating multi-source logs within Splunk, tracing attack paths from initial access to execution.
- Perform basic static and dynamic triage of suspicious files, scripts, and registry modifications.
- Execute authorized containment actions during live incidents, including isolating hosts via EDR, revoking compromised credentials, or blocking malicious IPs.
- Partner with IT and Infrastructure teams to provide technical remediation advice (e.g., patching, configuration changes) following a security event.
- Review response playbooks and tune Splunk search logic to continually reduce future false positives.
Job Requirements & Qualifications
Experience & Shift Availability
- Total Security Experience: Minimum of 2–4 years of dedicated experience working inside a Security Operations Center (SOC) or in an IT Support/Network Operations (NOC) role with a strong security focus.
- Track Record: Proven ability to manage, document, and contain mid-to-high severity security incidents.
- Shift Flexibility: Full availability and willingness to work in a rotating 24/7/365 shift schedule (including nights, weekends, and holidays).
Technical Skills & Splunk Expertise
- Splunk Mastery: Strong hands-on experience navigating, querying, and building custom dashboards within Splunk using Search Processing Language (SPL).
- EDR/XDR Capabilities: Experience running device checks, tracking process trees, and executing remote containment via tools like CrowdStrike Falcon, Microsoft Defender for Endpoint, or Cortex XDR.
- Infrastructure & Networking: Solid grasp of core networking fundamentals (TCP/IP, DNS, DHCP, routing) and ability to inspect system logs across Windows and Linux environments.
- Framework Awareness: Practical knowledge of mapping malicious activity patterns directly against the MITRE ATT&CK matrix.
Preferred Certifications & Education
- Education: Bachelor’s degree in Computer Science, Cyber Security, IT, or equivalent practical experience.
- Certifications (Highly Prioritized): Holds or is pursuing intermediate designations such as:Splunk Core Certified Power User / Splunk Enterprise Security Certified AdminCompTIA Security+ or Cybersecurity Analyst (CySA+)GIAC Certified Incident Handler (GCIH)