Lead, Security(T1 SOC Analyst)
Core
SOC analyst responsible for 24/7 incident triage, investigation, and response using SIEM and EDR tools to protect client infrastructure.
Role type
SOC Analyst (Incident Response & Threat Detection)
Builds
Incident response workflows and threat mitigation strategies for enterprise clients
Domain
Cybersecurity / Security Operations Center (SOC)
Deliverable
client delivery
Required skills
SIEM operation, EDR operation, incident triage, log analysis, threat investigation, remediation tracking, playbook documentation
Preferred skills
SOAR basics, MITRE ATT&CK framework, Cyber Kill Chain, technical team coordination
Technologies
QRadar, Splunk, Microsoft Sentinel, MS Defender
Responsibilities
Conduct preliminary incident triage and set priority, utilize intrusion detection and security scanning systems for investigation, coordinate security incident response and containment, update SOC documentation and investigation playbooks, correlate various security events, review and triage endpoint detection data
Seniority
Junior to Mid-level (0-2 years experience)