Source description
About the role
Responsibilities Triage and investigate security alerts escalated from Tier 1 analysts, determining scope, impact, and root cause Perform in-depth analysis of endpoint, network, and log data using SIEM, EDR, and threat intelligence platforms Lead incident response activities including containment, eradication, and recovery Hunt proactively for threats and indicators of compromise (IOCs) across the environment Develop and refine detection rules, playbooks, and runbooks to improve SOC efficiency Mentor Tier 1 analysts and provide guidance on complex investigations Coordinate with IT, engineering, and business teams during active incidents Document findings and produce clear, actionable incident reports for technical and non-technical audiences Track and manage incidents through the full lifecycle using ticketing systems Contribute to post-incident reviews and recommend improvements to security controls Required Qualifications 3+ years of experience in SOC, incident response, or cybersecurity operations role Proficiency with SIEM platforms (e.g., Splunk, Microsoft Sentinel, QRadar) Hands-on experience with EDR tools (e.g., CrowdStrike Falcon, Microsoft Defender, Carbon Black) Strong understanding of the MITRE ATT&CK framework and its application to threat detection Solid knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, firewalls, proxies) Experience analyzing malware behavior, phishing campaigns, and intrusion attempts Familiarity with log analysis across Windows, Linux, and cloud environments Ability to write and run queries in SPL, KQL, or equivalent query languages Preferred Qualifications Relevant certifications: Security+, CySA+, CEH, GCIH, GCIA, or equivalent Experience with cloud security monitoring (AWS, Azure, or GCP) Scripting skills in Python, PowerShell, or Bash for automation and analysis Familiarity with SOAR platforms and playbook automation Prior experience with threat intelligence platforms (e.g., MISP, ThreatConnect) Responsibilities Triage and investigate security alerts escalated from Tier 1 analysts, determining scope, impact, and root cause Perform in-depth analysis of endpoint, network, and log data using SIEM, EDR, and threat intelligence platforms Lead incident response activities including containment, eradication, and recovery Hunt proactively for threats and indicators of compromise (IOCs) across the environment Develop and refine detection rules, playbooks, and runbooks to improve SOC efficiency Mentor Tier 1 analysts and provide guidance on complex investigations Coordinate with IT, engineering, and business teams during active incidents Document findings and produce clear, actionable incident reports for technical and non-technical audiences Track and manage incidents through the full lifecycle using ticketing systems Contribute to post-incident reviews and recommend improvements to security controls Required Qualifications 3+ years of experience in SOC, incident response, or cybersecurity operations role Proficiency with SIEM platforms (e.g., Splunk, Microsoft Sentinel, QRadar) Hands-on experience with EDR tools (e.g., CrowdStrike Falcon, Microsoft Defender, Carbon Black) Strong understanding of the MITRE ATT&CK framework and its application to threat detection Solid knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, firewalls, proxies) Experience analyzing malware behavior, phishing campaigns, and intrusion attempts Familiarity with log analysis across Windows, Linux, and cloud environments Ability to write and run queries in SPL, KQL, or equivalent query languages Preferred Qualifications Relevant certifications: Security+, CySA+, CEH, GCIH, GCIA, or equivalent Experience with cloud security monitoring (AWS, Azure, or GCP) Scripting skills in Python, PowerShell, or Bash for automation and analysis Familiarity with SOAR platforms and playbook automation Prior experience with threat intelligence platforms (e.g., MISP, ThreatConnect)
More at Company Name