About the role
The Security Threat Analyst is an entry-level role within the Security Operations Center (SOC) responsible for monitoring and triaging security events in a 24x7x365 environment. The role involves reviewing real-time security alerts, assessing their relevance and severity, and performing initial analysis and response activities to support incident management. The analyst is responsible for monitoring the health of security tools, sensors, and endpoints, investigating potential threats, and escalating incidents as needed. Additionally, the role supports asset discovery, vulnerability assessment activities, remediation tracking, and reporting, while keeping current with emerging cybersecurity threats, industry trends, and regulatory security requirements.
Key responsibilities
- Monitor and analyze security events from multiple SOC log sources to assess the relevance, severity, and urgency of potential threats.
- Continuously monitor the health and availability of security sensors, monitoring platforms, and endpoint security solutions.
- Perform system and network inventory validation, collect and analyze logs, investigate security alerts, identify root causes, and execute initial incident response activities.
- Create and document alert tickets, gather relevant incident information, follow established incident response playbooks, and escalates cases to Level 2 analysts for further investigation and resolution.
- Conduct vulnerability scans, review assessment results, and support the tracking of remediation activities.
- Administer and maintain security monitoring tools, onboard log sources, and contribute to the optimization and tuning of security systems.
- Develop and enhance security event monitoring and threat detection use cases to improve overall detection capabilities.
- Recommend improvements to SOC processes, procedures, policies, and incident response playbooks to strengthen security operations.
- Stay informed of emerging cyber threats, vulnerabilities, threat intelligence, and relevant regulatory security requirements.
- Prepare security reports and documentation to support operational and compliance requirements.
About you
- Bachelor's Degree in a relevant area of study with a preference for Information Security, Computer Science or Computer Engineering
- Foundational understanding of IP networking, routing and switching, including multiple operating systems (Windows, Solaris, *nix) and system administration.
- Self-starter, analytical thinker and genuine passion for Information Security.
- Basic understanding of Information Security concepts and practices
- Detail oriented with strong organizational and analytical skills
- Programming skills as well as host, network and application investigative skills
- Knowledgeable in security technology like SIEM, anti-malware, firewall, IPS/IDS, logging, monitoring and vulnerability management.
- Basic knowledge of client-server applications, multi-tier web applications, relational databases.
- Task and delivery management skills
- Good written and verbal communication and presentation skills
About us
At Metrobank, we don't simply hire employees—we hone future leaders. We provide opportunities that enhance your skills and unlock your talents, helping you evolve into a well-rounded individual. We supply you with all the pieces you need to do your best work, unleashing your full potential to help you secure your future and lead a fulfilling career. With Metrobank's strong heart for the community, you have the chance to give back and make worthwhile contributions to our nation's economic and social development.