Overview
A Security Operations Center (SOC) Analyst is an operational role, focusing on real-time security event monitoring and security incident investigation. They will perform an in-depth analysis of evidence, identify the malicious operations, and evaluate the real impact to solve quickly and efficiently.
Responsibilities
- Continuously monitors security events and triages security alerts from the SOC channel (Open XDR Platform) based on the security event severity, escalates to Level 2 Security Analyst, and/or customer as appropriate to perform further investigation and resolution.
- Responds to security incidents if necessary or as required.
- Collects data and context necessary to initiate Level 2 escalation. Works closely with Level 2 & Level 3 team towards the continuous improvement of the service.
- Recommend enhancements to SOC security processes, procedures, and policies.
- Participate in security incident management and vulnerability management processes.
- Participate in evaluating, recommending, implementing, and troubleshooting security solutions and evaluating IT security of the new IT Infrastructure systems.
- Works as part of a team to ensure that corporate data and technology platform components are safeguarded from known threats.
- Communicate effectively with customers, teammates, and management.
- Provide input on tuning and optimization of security systems.
- Document and maintain customer build documents, security procedures, and processes.
- Staying up to date with emerging security threats including applicable regulatory security requirements.
- Monitors the health of customer security sensors and Open XDR Platform. Delivers scheduled and ad hoc reports.
Qualifications
- Job Type: Full-time
- Education: Bachelor\'s (Preferred)
- Experience: SOC Analyst 1: 1 year (Preferred)
- License/Certification: Cyber Security Training Certification/s (Preferred)
- Preferably at least 1 year previous Security Operations Centre Experience in conducting security investigations.
- Fresh graduates are welcome to apply with relevant certifications.
- Good knowledge of IT including multiple operating systems and system administration skills (Windows, Solaris, Unix).
- Knowledgeable of client-server applications, multi-tier web applications, relational databases, firewalls, VPNs, and cybersecurity solutions like EDR and XDR.
- Understanding of security incident management, malware management, and vulnerability management processes.
- Scripting skill set (Bash, Python, Ruby, Perl, PowerShell) will be considered a plus.
- Security monitoring experience with one or more XDR/SOAR/SIEM technologies and intrusion detection technologies.
- Experience with web content filtering technology - policy engineering and troubleshooting.
- Strong understanding of networking principles including TCP/IP, WANs, LANs, and commonly used Internet protocols such as SMTP, HTTP, FTP, POP, and LDAP.
- Detail-oriented with strong organizational and analytical skills.
- Strong written communication skills and presentation skills.
- Excellent English written and verbal skills.
- Must be willing for a Shift work.
Benefits
- Benefits:
- Additional leave
- Company Christmas gift
- Company events
- Health insurance
- Life insurance
- Opportunities for promotion
- Promotion to permanent employee
- Schedule: Day shift, Rotational shift, Shift system
- Supplemental Pay: 13th-month salary