SOC Security Analyst

Gruve

Singapore

On-site

SGD 70,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Gruve is seeking a highly skilled Security Analyst to join our SOC team in Singapore. You will monitor SIEM and XDR/EDR, investigate alerts, and provide precise threat insights with recommendations to customers.

You will triage incidents, document findings, and collaborate with cross-functional teams to improve detection, response playbooks, and security operations. Strong scripting basics and communication are essential.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field.
  • 3+ years of experience in security operations, SIEM, or IT security.
  • Hands-on experience with SIEM tools (e.g., Splunk, ArcSight, QRadar), endpoint protection, and IDS/IPS.
  • Strong understanding of IT infrastructure, networking, and core cybersecurity principles.
  • Excellent communication, problem-solving skills, and attention to detail.

Responsibilities

  • Analyze and respond to security alerts escalated from L1 analysts or generated by security monitoring tools (SIEM, IDS/IPS, EDR).
  • Incident triage: conduct initial analysis of potential security incidents to determine severity, impact, and scope, including identifying false positives.
  • Incident escalation: escalate incidents to L3 SOC analysts for deeper investigation and remediation.
  • Containment: take appropriate containment actions to limit impact of ongoing security incidents.
  • Incident documentation: document and report security incidents for analysis and compliance requirements.
  • Proactive threat hunting: analyze logs to identify threats and vulnerabilities.
  • Monitor security systems to detect anomalies and potential attacks.
  • Alert tuning to improve detection and reduce false positives.
  • Security systems and tools management: configure and maintain security tools.
  • Log review: review logs to identify security events.
  • SIEM & XDR management: fine-tune and search security data.
  • Mentor L1 analysts and collaborate with other teams to address vulnerabilities.
  • Engage with customers during incidents and provide expert guidance.
  • Develop and troubleshoot XDR playbooks and automation workflows.
  • Prepare incident reports and generate logs/metrics for management.

Skills

Analytical thinking
Communication skills
Attention to detail
Problem-solving

Education

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field

Tools

Splunk
ArcSight
QRadar
SOAR platforms

Job description

About the role

We are seeking a highly skilled Security Analyst to join our Security Operations Center (SOC) team. The ideal candidate should have a strong foundation in SIEM monitoring & XDR or EDR solutions, and security analysis, with hands‑on experience in investigating and responding to security alerts. This role requires expertise in reviewing and analyzing L1 alerts, providing detailed recommendations, and engaging with customers for incident handling. The candidate should also have a basic SIEM administration background and Python scripting skills for troubleshooting and playbook development.

Key Roles & Responsibilities
Incident Detection and Response
  • Analyze and respond to security alerts escalated from L1 analysts or generated by security monitoring tools (SIEM, IDS/IPS, EDR).
  • Incident triage: conduct initial analysis of potential security incidents to determine severity, impact, and scope, including identifying false positives.
  • Incident escalation: if necessary, escalates incidents to L3 SOC analysts for deeper investigation and remediation.
  • Containment: take appropriate containment actions to limit the impact of ongoing security incidents (e.g., isolating affected systems, blocking malicious IP addresses).
  • Incident documentation: accurately document and report security incidents in a clear and comprehensive manner for later analysis and compliance requirements.
Threat Hunting and Monitoring
  • Proactive threat hunting: identify potential threats and vulnerabilities by analyzing logs, network traffic, and other security data to find hidden threats or weaknesses.
  • Monitor security systems: regularly monitor and assess security infrastructure, including firewalls, intrusion detection systems, and endpoint protection tools, to detect anomalies and potential attacks.
  • Alert tuning: adjust and refine alerts within security tools (SIEM, XDR) to improve detection and reduce false positives.
Security Tool Management
  • Security systems and tools management: assist in configuration, management, and maintenance of security tools (e.g., SIEM & XDR tools) to ensure effective threat detection.
  • Log review: review logs from various sources such as network devices, servers, and applications to identify security events or irregular activities.
  • SIEM & XDR management: ensure SIEM & XDR tools are operating properly, fine‑tune them for better accuracy, and perform searches on security data.
Collaboration and Escalation
  • Work with L1 analysts: provide guidance and mentorship to L1 analysts on how to identify and escalate security incidents appropriately.
  • Collaborate with other teams: coordinate with internal teams (network security, IT operations, application security, etc.) to address vulnerabilities, incidents, and other security concerns.
  • Incident escalation to L3: for complex or advanced incidents, escalates issues to L3 analysts for deeper investigation and remediation.
Customer Communication & Incident Handling
  • Engage with customers during security incidents and provide expert guidance.
  • Conduct technical discussions to explain security threats and mitigation steps.
  • Collaborate with internal and external teams for incident resolution.
Playbook Management & Troubleshooting
  • Understand and modify XDR playbooks to automate security operations.
  • Troubleshoot playbook errors and optimize automation workflows.
  • Identify gaps in existing security automation and recommend enhancements.
Security Reporting and Documentation
  • Prepare incident reports: document detailed incident reports and provide analysis on the severity and impact of security events for management and other stakeholders.
  • Generate logs and metrics: provide regular reports and metrics on security operations, highlighting trends, incidents, and areas of improvement.
  • Compliance reporting: ensure that incident records meet internal and external compliance and regulatory requirements (e.g., GDPR, HIPAA, PCI DSS).
Continuous Improvement
  • Contribute to the development and improvement of SOC procedures, workflows, and tools to enhance the efficiency of security monitoring and incident response.
  • Stay current with threats: continuously update knowledge on emerging cybersecurity threats, trends, tools, and techniques to improve threat detection and response.
  • Contribute to training: assist in training and developing junior staff (L1 analysts), ensuring the team’s overall readiness to handle incidents.
Basic Qualifications
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • 3+ years of experience in security operations, SIEM, or IT security with solid foundational knowledge.
  • Hands‑on experience with SIEM tools (e.g., Splunk, ArcSight, QRadar), endpoint protection, and IDS/IPS.
  • Strong understanding of IT infrastructure, networking, and core cybersecurity principles.
  • Excellent communication, problem‑solving skills, and attention to detail.
Preferred Qualifications
  • Relevant security certifications such as CISSP, CISM, GCIA, GCIH, or equivalent.
  • Experience with modern SIEM platforms (e.g., Palo Alto XSIAM, Google SecOps, FortiSIEM, Splunk).
  • Exposure to SOAR platforms and security automation workflows.
  • Knowledge of cloud security across AWS, Azure, or GCP environments.
  • Experience working in hybrid or cloud‑based SOC environments.

Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Security Analyst: Threat Detection & Response
SOC Security Analyst: Threat Detection & Response

Gruve • Singapore

On-site
Senior SOC Incident Response & Threat Hunter
Senior SOC Incident Response & Threat Hunter

Gruve • Singapore

On-site
SGD 120,000 - 160,000
SOC Security Consultant
SOC Security Consultant

Gruve • Singapore

On-site
SGD 120,000 - 160,000
Cybersecurity SOC Analyst (0016 Mar 2026)
Cybersecurity SOC Analyst (0016 Mar 2026)

Internetwork Expert • Singapore

On-site
SGD 50,000 - 70,000
Cybersecurity SOC Analyst
Cybersecurity SOC Analyst

St Engineering • Singapore

On-site
SGD 48,000 - 72,000
L3 SOC analyst & SOC Manager
L3 SOC analyst & SOC Manager

INSYGHTS SECURITY PTE. LTD. • Singapore

On-site
SGD 120,000 - 160,000
Security Analyst L2
Security Analyst L2

ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD. • Singapore

On-site
SGD 70,000 - 95,000
SOC Analyst
SOC Analyst

FLINTEX CONSULTING PTE. LTD. • Singapore

On-site
SGD 60,000 - 90,000
SOC Analyst
SOC Analyst

UNITED OVERSEAS BANK LIMITED • Singapore

On-site
SGD 45,000 - 65,000
Cybersecurity SOC Manager
Cybersecurity SOC Manager

NETS • Singapore

On-site
SGD 120,000 - 240,000