Attack Monitoring Analyst (GSOC)
Core
Triage security events, respond to cyber security incidents, and improve defensive capabilities within a Global Security Operations Centre (GSOC).
Role type
Associate-level Attack Monitoring Analyst (IC)
Builds
Incident response playbooks, monitoring dashboards, and threat intelligence reports
Domain
Cybersecurity / Financial Markets Infrastructure
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
SIEM operation (Splunk/QRadar/LogRhythm), network architecture (TCP/IP), security event analysis & triage, incident handling, root-cause identification, threat intelligence research, scripting (Python/PowerShell/Java/C#), vulnerability management
Preferred skills
OSCP, GIAC, CCNA certifications, experience with attacker tools and techniques
Technologies
Splunk, QRadar, LogRhythm, Python, PowerShell, Java, C#
Responsibilities
Triage security events and respond to incidents using playbooks; Operate SIEM tools for investigations and dashboard development; Research and collect threat intelligence; Develop or improve run books and use cases; Stay updated on vulnerabilities and countermeasures; Identify, respond, and remediate cyber events
Seniority
Associate, hands-on IC