Security Operations Analyst (Cyber Defense Operations)
Core
Monitor, detect, investigate, and respond to cyber threats across enterprise, cloud, network, and endpoint environments in a 24/7 SOC.
Role type
Security Operations Analyst (SOC)
Builds
Security monitoring, alert triage, incident response, and threat detection capabilities
Domain
Cybersecurity / Cloud / Enterprise Security
Required skills
SIEM platforms, EDR solutions, log analysis, incident response, cloud security, network monitoring, Microsoft security technologies, Linux/Windows/macOS administration
Preferred skills
Incident Response Tier-1/Tier-2 experience, AWS security monitoring, scripting (Python/PowerShell/Bash/Ruby), security certifications
Technologies
Splunk, QRadar, ArcSight, Microsoft Sentinel, ELK, Microsoft Defender for Endpoint, CrowdStrike, Azure, AWS, GCP
Responsibilities
Monitor and triage security alerts, analyze host and network logs, investigate suspicious activity and identify root causes, support incident response and remediation, tune detection rules to reduce false positives, prepare security reports and findings, contribute to SOC procedures and documentation
Seniority
Mid-Senior, hands-on IC