SOC Analyst - Tier 1 (Managed SOC)
Indexed description
Responsibilities:
Security Monitoring & Event Analysis
- Provide continuous 24x7 monitoring of customer and enterprise security environments through shift-based operations.
- Monitor and analyze security events generated from SIEM platforms, IDS/IPS solutions, Endpoint Detection & Response (EDR) tools, Firewalls, Email security gateways, Web security solutions and Cloud security platforms
- Review and assess security alerts to determine whether activity represents a legitimate security threat or a false positive.
- Perform initial event validation, classification, and prioritization based on severity, risk, and potential business impact.
- Identify suspicious behavior, indicators of compromise (IOCs), and anomalous activities requiring further investigation.
- Perform first-level analysis and triage of security alerts and events.
- Create and manage incident tickets within approved incident management platforms.
- Categorize incidents based on Severity, Impact, Urgency and Threat classification
- Escalate validated incidents to SOC Analyst - Tier 2 teams in accordance with approved escalation procedures.
- Ensure escalations include complete and accurate investigation details to support efficient handover and further analysis.
- Maintain incident tracking and ensure timely updates throughout the incident lifecycle.
- Utilize SIEM platforms to Monitor security events, Review alerts, Execute predefined searches and queries, Support basic investigations
- Support operational activities including Alert validation, Monitoring dashboard review, Log analysis and Security event correlation
- Assist with identifying false positives and escalating tuning recommendations where required.
- Support the overall effectiveness and reliability of monitoring operations.
- Maintain accurate records of investigations, observations, and escalation activities.
- Document security incidents and monitoring activities in accordance with operational procedures.
- Participate in shift handovers and ensure continuity of investigations between teams.
- Support operational reporting and SOC performance metrics activities.
- Follow approved SOC procedures, playbooks, and operational standards.
- Ensure compliance with Internal security policies and Customer contractual obligations
- Handle customer information with strict confidentiality and professionalism.
- Participate in training, simulation exercises, and continuous improvement initiatives.
- Maintain awareness of emerging cybersecurity threats and attack techniques.
- Minimum 1 year of SOC operations experience
- Familiarity with SIEM consoles, alert triage, and SOC monitoring workflow; willingness to work rotating shifts.
- Foundational networking and operating-system knowledge is preferable.
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related field.
- Security +, CEH or any relevant certification preferred
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search