Scope of Work:
• Operate within a 24/7 Security Operations Center (SOC) environment, ensuring round-the-clock coverage for security monitoring and incident response.
• Monitor alerts and notifications generated by security systems and tools, identifying potential security incidents.
• Investigate and analyze security alerts, discerning false positives from genuine threats, and escalating as per defined protocols.
• Collaborate with Tier-2 analysts and assist in incident response activities, contributing to effective containment and resolution.
• Follow established procedures for analyzing and escalating critical security incidents, adhering to response timelines.
• Monitor network and system logs, identifying suspicious activities and anomalies that could indicate security breaches.
• Assist in generating incident reports and documenting the analysis, actions taken, and outcomes for future reference.
• Participate in routine security assessments, such as vulnerability scans, and assist in evaluating results.
• Maintain awareness of current security threats and trends, staying informed about emerging attack techniques.
• Follow and document standard operating procedures for security monitoring and incident response.
• Contribute to continuous improvement efforts by suggesting enhancements to processes, tools, and procedures.
• Support security team members in creating and fine-tuning security use cases for better detection capabilities.
• Maintain a strong understanding of the organization's network, systems, and applications to effectively identify anomalies.
• Assist in reviewing and analyzing threat intelligence reports to understand potential risks to the organization.
• Participate in training and skill development programs to enhance security knowledge and expertise.
Skills
Skills:
• Incident Detection
• Security Event Monitoring
• Basic Cybersecurity Concepts
• Networking Fundamentals
• Communication Skills
• Threat Identification
• Incident Triage
• Security Tools Familiarity
Certification (Optional but beneficial):
- CompTIA Security+
- Microsoft Certified: Security Operations Analyst Associate