Cyber Security Analyst
Core
Operational backbone of the SOC handling day-to-day monitoring, triage, investigation, and initial incident response.
Role type
Mid-level SOC Analyst
Builds
SOC operational standards, runbooks, and detection tuning
Domain
Cybersecurity / Cloud Security (AWS)
Deliverable
production ML models | product features | dashboards & analysis | client delivery
Required skills
SIEM alert triage, AWS security services, incident response (containment/eradication/recovery), runbook execution, detection tuning, dashboard monitoring, retrospective analysis
Preferred skills
Detection authoring, scripting (Terraform/Python/PowerShell), AWS-native tooling (GuardDuty/Security Hub/CloudTrail/Detective)
Technologies
SIEM, AWS, Terraform, Python, PowerShell, GuardDuty, Security Hub, CloudTrail, Detective
Responsibilities
Monitor, triage, and investigate security alerts; Review security event data and escalate incidents; Execute runbooks and contribute to their improvement; Coordinate with infrastructure and application teams during incidents; Feed detection tuning recommendations to senior team; Contribute to dashboard monitoring and retrospective analysis
Seniority
Mid-level, hands-on IC