
Enable job alerts via email!
Generate a tailored resume in minutes
Land an interview and earn more. Learn more
A leading professional services firm is seeking an L1 SOC Analyst in Kuala Lumpur. You will monitor alerts and investigate complex cybersecurity issues as part of a dedicated team. Key responsibilities include triaging alerts, collaborating with server owners, handling Jira tickets, and potentially escalating security incidents. The ideal candidate should have a degree in a relevant field and possess attention to detail and strong communication skills. Opportunity for growth in threat hunting skills is available in this role.
As a L1 SOC Analyst, you'll work as part of a team of problem solvers, helping to solve complex business issues from strategy to execution. PwC Professional skills and responsibilities for this management level include but are not limited to:
Alert Triage & Investigation
• Monitor for newly triggered alerts. Also look for alerts not yet marked as Open or Closed
• Collect more information to support the theory of the alerts under assessment
• Correlate alerts with other security devices
• Investigate the impact of the alerts
Ensure that shift handovers are conducted clearly and concisely, which includes:
• Participating in shift handover process
• Conducting shift handover
• Preparing shift handover report
• Communicating shift handover information to next shift personnel
Monitor and investigate if the logs from the stopped flowing to SIEM. Reach out to the Server owner, generate a list and work on the list, report the ones resolved and the method used.
• Linux - Syslogs - get in touch with server owner
• Windows - check for permission, user status (disabled/activate), password expiry (local user). User ID for windows collections is Irsvrcollector.
Attend to Jira tickets sent to the client. Response to inquiry or forward the ticket to the respective group/team.
Detect and report ticket with log parser issue to Infra/SIEM Engineer.
Detect and report ticket with False Alarm to Infra/SIEM Engineer.
Authorise to review and analyse alerts generated by security tools and systems.
Empower to escalates potential security incidents to higher-level analysts (L2 or L3) based on predefined criteria.