Role Overview
As an L1 SOC Analyst, you will be responsible for monitoring security alerts, performing initial triage and investigation, identifying potential security incidents, and escalating confirmed or suspicious activities to the appropriate teams.
You will work with technologies including SIEM, SOAR, EDR, Cloud, Network, Datacenter, Application and Database.
Key Responsibilities
- Monitor security alerts across SIEM, EDR, and other integrated security platforms.
- Perform initial alert triage and validation.
- Investigate suspicious activities using available logs and security telemetry.
- Identify false positives and document investigation findings.
- Classify alerts and incidents based on severity and potential business impact.
- Escalate confirmed security incidents to L2/L3 analysts and customer teams according to defined procedures.
- Support investigation of endpoint, identity, email, cloud, network, and application-related security events.
- Maintain accurate incident and investigation documentation.
- Follow SOC SOPs, playbooks, and runbooks during investigations.
- Participate in shift handovers and ensure proper communication of ongoing incidents.
- Monitor assigned security platforms for operational issues and raise platform-related problems.
- Support preparation of daily, weekly, and monthly SOC reports.
- Contribute to knowledge‑base updates and continuous improvement of SOC processes.
- Maintain awareness of current cybersecurity threats, attack techniques, and vulnerabilities.
Technical Areas
- Microsoft Sentinel
- Crowdstrike
- SentinelOne
- Huntress EDR
- Microsoft 365 Security
- Amazon Web Services (AWS)
- Firewalls and VPN
- Web Application Firewall (WAF)
- Application and Database Logs
- MITRE ATT&CK
Required Skills
- Understanding of cybersecurity concepts.
- Understanding of networking fundamentals such as TCP/IP, DNS, HTTP/HTTPS, VPN, and firewalls.
- Basic understanding of Windows and Linux environments.
- Understanding of authentication, authorization, and MFA.
- Ability to analyze logs and identify suspicious activity.
- Good analytical and problem‑solving skills.
- Strong documentation and communication skills.
- Willingness to work in rotational shifts.
Good to Have
- Experience with Microsoft Sentinel or another SIEM.
- Experience with EDR/XDR platforms.
- Microsoft security certifications such as SC-200 or AZ-500.
- Security+ or equivalent cybersecurity certification.
- Knowledge of KQL.
- Understanding of MITRE ATT&CK.
- Basic knowledge of incident response and threat intelligence.