Source description
About the role
What You Will Do : Monitor security events and alerts across SIEM, EDR, IDS/IPS, firewalls, endpoint tools, and other security platforms in real-time Perform initial triage of alerts to identify false positives vs. genuine security incidents Execute predefined runbooks and standard operating procedures (SOPs) for common alert types Document all alerts, investigations, and actions in the incident ticketing system with clear, concise notes Escalate confirmed or high-priority incidents to Level 2 analysts with appropriate context and supporting evidence Analyze basic logs, network traffic, and indicators of compromise (IOCs) under guidance Assist with maintaining and tuning detection rules and monitoring dashboards (with supervision) Participate in shift handovers, team briefings, and continuous improvement discussions Stay current on emerging threats, basic attack techniques, and SOC tooling through on-the-job learning and training Clear career progression path: Level 1 Level 2 Level 3 / Incident Responder What You Will Need : Must have a bachelor s degree in Cybersecurity, Computer Science, Information Technology, or related field (or equivalent experience) Minimum 1 year of experience in IT, cybersecurity, or a related field Strong interest in cybersecurity and willingness to learn in a fast-paced, 24/7 environment Basic understanding of networking fundamentals (TCP/IP, DNS, HTTP/S, ports/protocols) Familiarity with common security concepts: malware, phishing, brute force, privilege escalation, etc Ability to read and interpret logs and alerts (prior SIEM exposure is a plus but not required) Excellent written and verbal communication skills for clear incident documentation and escalation Strong attention to detail and ability to work methodically under time pressure Comfortable working rotating shifts (including nights/weekends) What Would Be Nice To Have : Exposure to CompTIA Security (or equivalent entry-level certification like CySA, Network, Google Cybersecurity Certificate) Exposure to SIEM platforms (Splunk, Elastic, Microsoft Sentinel, QRadar, etc.) Basic scripting knowledge (PowerShell, Python, or similar) for log querying or automation Experience with EDR tools (ReliaQuest/Greymatter, Microsoft Defender, SentinelOne, CrowdStrike, etc.) Understanding of MITRE ATT&CK framework basics Excellent communication skills, with strong verbal and writing proficiencies Ability to positively influence and persuade individuals of varying levels Demonstrated ability to learn and document new technologies/solutions Strong work ethic with commitment and time management skills Ability to exercise judgement within procedures and practices to determine appropriate action Ability to manage and prioritize multiple work requirements to meet deadlines Ability to work independently and in a team environment Good planning, commitment, and time-keeping skills Excellent Planning, Reasoning, Analytical and problem-solving skills Prior experience in working as part of a multi-national corporation with diverse and geographically dispersed team A proactive customer centric approach and excellent learning skills
More at Guidehouse