SOC Analyst L1 (Blue Team)
Core
Monitoring security alerts, performing initial event analysis, and executing incident response procedures within a Blue Team environment.
Role type
SOC Analyst L1 (Blue Team)
Builds
Incident response workflows and security monitoring capabilities
Domain
Cybersecurity / IT Operations
Deliverable
client delivery
Required skills
SIEM/SOAR platform operation, incident analysis, log analysis, ticketing system management, knowledge base maintenance, ITIL framework familiarity
Preferred skills
ITIL certification, ISO27001 knowledge, CEH certification, BTL1 certification, CompTIA Security+ certification
Technologies
SIEM, SOAR, Remedy
Responsibilities
Monitor security alerts and events using SIEM and SOAR tools; Perform initial incident analysis following predefined playbooks; Escalate incidents to L2 when deeper investigation is required; Record, document, and update all tickets; Maintain and update the knowledge base
Seniority
Mid-level, hands-on IC