Analista de Respuesta a Incidentes SOC (24/7)
Core
Detect, investigate, and respond to security incidents in real-time to protect critical assets and infrastructure.
Role type
SOC Incident Response Analyst (24/7)
Builds
Incident response procedures and threat containment strategies
Domain
Cybersecurity / SOC Operations
Deliverable
client delivery
Required skills
SIEM platforms (Splunk, ELK Stack, ArcSight), log analysis, network/system logs analysis, incident response frameworks (NIST, MITRE ATT&CK), Windows/Linux OS fundamentals, network protocols, threat prioritization, incident documentation, stakeholder communication
Preferred skills
Threat hunting, malware analysis, digital forensics, scripting (Python, Bash, PowerShell), cloud security monitoring, IDS/IPS, vulnerability management, incident management tools
Technologies
Splunk, ELK Stack, ArcSight, Python, Bash, PowerShell
Responsibilities
Monitor and analyze security alerts from SIEM platforms, conduct thorough incident investigations including data collection and evidence preservation, execute incident response procedures and escalation protocols, document incident details and conclusions, communicate incident status to stakeholders, classify and evaluate security event severity, collaborate to contain, eradicate, and recover from incidents, maintain knowledge of organizational security infrastructure, participate in threat intelligence sharing, support development of response procedures, assist in user security awareness activities
Seniority
Mid-level, hands-on IC