Security Analyst, CSOC
Core
Monitor and analyze security events, investigate intrusions, and support rapid containment and remediation in a 24/7 Cyber Security Operations Center.
Role type
L1 Security Analyst (SOC) (via careerplan.io/jobs/fe097c98-5813-4a71-8979-0422adfd0156-security-analyst-csoc-at-jobgether)
Builds
Enterprise defenses against evolving cyber threats
Domain
Cybersecurity / SOC Operations
Required skills
Splunk SIEM, security log analysis, incident response, threat analysis, forensic investigation, network architecture (TCP/IP, OSI), intrusion detection technologies, malware analysis, web application architecture, Active Directory, protocol analysis (HTTP, SMTP, DNS)
Preferred skills
CompTIA Security+, AI productivity tools (ChatGPT, Copilot)
Technologies
Splunk, EDR, firewalls, IDS/IPS, proxies, NIDS, HIDS
Responsibilities
Monitor and analyze network traffic, security events, alerts, and threat indicators; Investigate security incidents and intrusion attempts by correlating information from multiple sources; Analyze logs from SIEM, EDR, firewalls, proxies, NIDS, HIDS, and host systems to identify malicious activity; Independently identify, classify, contain, investigate, document, and eradicate security threats; Perform L1 security event and incident analysis, identify false positives, correlate related events, and escalate confirmed or high-risk incidents; Assess the potential impact of incidents and determine the remediation actions required to reduce risk and restore secure operations; Collaborate with engineering, network, application, and security teams to support effective incident resolution; Apply practical AI tools and automation where appropriate to streamline analysis and improve response efficiency.
Seniority
Mid-level, hands-on IC