- At least 1 year of experience as a security analyst
- Proficient in investigating s related to phishing, malware, and similar threats.
- Solid understanding of computer security and networking concepts
- Experience with SIEM or similar security tools.
- Knowledgeable about endpoint protection tools
- Skilled in analysing network traffic, interpreting logs, and examining packet capture.
- Strong critical thinking and analytical abilities
- Excellent written and verbal communication skills
- Experience managing and analysing s from security tools is a plus.
- Familiarity with cloud solutions is advantageous.
- Relevant certifications are a plus.
- Monitor, triage, and classify security s/incidents within defined SLAs and prioritize cases based on severity.
- Perform first-level investigation and threat analysis using SIEM/SOAR and other security tools.
- Collect, validate, and document evidence, findings, and investigation outcomes for each assigned case.
- Escalate suspicious, complex, or high‑severity incidents to L1/L2 analysts and technical leads as required.
- Monitor client communications and security updates through SOAR, Teams, shared mailboxes, and other channels.
- Ensure effective shift handover with clear case status, pending actions, and critical updates.
- Identify and report process or detection gaps to improve SOC/MDR service quality.
- Support L2/Lead Analysts with security data and reporting for weekly, monthly, and QBR activities.
Role Description
Skills and Qualifications
- At least 1 year of experience as a security analyst
- Proficient in investigating s related to phishing, malware, and similar threats.
- Solid understanding of computer security and networking concepts
- Experience with SIEM or similar security tools.
- Knowledgeable about endpoint protection tools
- Skilled in analysing network traffic, interpreting logs, and examining packet capture.
- Strong critical thinking and analytical abilities
- Excellent written and verbal communication skills
- Experience managing and analysing s from security tools is a plus.
- Familiarity with cloud solutions is advantageous.
- Relevant certifications are a plus.
Principle Duties
- Monitor, triage, and classify security s/incidents within defined SLAs and prioritize cases based on severity.
- Perform first-level investigation and threat analysis using SIEM/SOAR and other security tools.
- Collect, validate, and document evidence, findings, and investigation outcomes for each assigned case.
- Escalate suspicious, complex, or high‑severity incidents to L1/L2 analysts and technical leads as required.
- Monitor client communications and security updates through SOAR, Teams, shared mailboxes, and other channels.
- Ensure effective shift handover with clear case status, pending actions, and critical updates.
- Identify and report process or detection gaps to improve SOC/MDR service quality.
- Support L2/Lead Analysts with security data and reporting for weekly, monthly, and QBR activities.
Skills
Security Operations Center, phishing, malware threats, SIEM or similar security tools, endpoint protection, Network traffic, interpreting logs, examining packet capture, SOC Monitoring, Triage, Incident Investigation, SIEM/SOAR, Threat Detection, Incident Escalation, Security Event Analysis