Role Summary
We are seeking an experienced Security Analyst to support Security Operations Center activities, including real-time security monitoring, incident detection, investigation, response, vulnerability assessment, and security event analysis. The candidate will work closely with infrastructure, network, server, and application teams to identify, investigate, contain, and remediate security threats while ensuring incidents are addressed within defined SLAs.
The role requires hands‑on experience with SIEM platforms, endpoint security tools such as CrowdStrike, next‑generation firewalls such as FortiGate, Windows/Linux environments, Active Directory, and ServiceNow.
Key Responsibilities
- Monitor and analyze security alerts and events generated from SIEM, EDR, firewalls, IDS/IPS, proxy servers, antivirus solutions, databases, applications, Windows/Linux servers, and other network security devices.
- Perform end‑to‑end security incident investigation and determine whether security events represent false positives or true security incidents.
- Perform root cause analysis and manage incidents in accordance with established Incident Response and Incident Management frameworks.
- Monitor network traffic and security logs to identify anomalous behavior, attempted compromises, and potentially malicious activity.
- Investigate user activity, sign‑in logs, and access privileges using Active Directory and related security controls.
- Escalate confirmed security incidents to appropriate infrastructure, network, server, application, and management teams and track incidents through closure.
- Create, manage, and track security incident tickets using ServiceNow, ensuring incidents are resolved within agreed SLAs.
- Configure and onboard security logs from firewalls, IDS/IPS, Windows servers, Linux servers, databases, and applications into monitoring platforms.
- Conduct vulnerability assessments across operating systems, ports, applications, hardware, servers, and network infrastructure.
- Coordinate vulnerability scans for critical servers and applications on weekly, monthly, and quarterly schedules.
- Prepare vulnerability, remediation, security incident, compliance, and operational reports.
- Analyze daily and monthly incident management reports and support security compliance activities.
- Collaborate with Network, Infrastructure, Server, and Application teams to troubleshoot and remediate security issues.
- Participate in knowledge‑sharing sessions, incident reviews, and lessons‑learned discussions to improve SOC capabilities and security processes.
Required Skills & Experience
- 3–5 years of relevant experience in Cybersecurity, Information Security, or Security Operations.
- Strong understanding of SOC operations, security monitoring, incident investigation, incident response, and log analysis.
- Experience with Endpoint Detection & Response / Endpoint Security, preferably CrowdStrike.
- Experience monitoring and analyzing firewalls, IDS/IPS, proxies, antivirus, email security, servers, databases, and network security devices.
- Working knowledge of FortiGate or similar next‑generation firewalls.
- Good understanding of Windows and Linux server security.
- Experience working with Active Directory, user access privileges, and authentication/sign‑in logs.
- Experience with ServiceNow or equivalent ITSM/ticketing platforms.
- Understanding of vulnerability assessment, remediation tracking, and vulnerability reporting.
- Ability to differentiate false‑positive and true‑positive security alerts through detailed investigation.
- Knowledge of SLA‑driven incident management and security escalation procedures.
- Strong analytical, troubleshooting, documentation, and communication skills.
Education
Bachelor’s degree in engineering, Computer Science, Information Technology, Cybersecurity, or a related discipline.