Back to search
CloudMile Linkedin · Posted 2d ago

Junior Security Operations Center Analyst (L1)

Jakarta

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

As a Security Operations Center (SOC) Analyst L1, you will serve as the first line of defense in detecting and responding to security threats across our client environments. This role is open to fresh graduates who are passionate about cybersecurity, as well as early-career or experienced professionals who want to deepen their hands-on SOC and SIEM expertise.


You will work closely with senior analysts and the SOC Lead while operating primarily on Google Security Operations (SecOps) and other modern security platforms. This role offers strong exposure to real-world incidents, structured processes, and continuous learning in a production SOC environment.


Key Responsibilities:

  • Security Monitoring: Monitor, analyze, and validate alerts generated from Google Security Operations (SecOps) and supporting security tools.
  • Alert Triage & Investigation: Perform initial investigation to assess alert severity, context, and potential impact.
  • Incident Escalation: Escalate confirmed incidents or suspicious activity to SOC L2 / SOC Lead with clear analysis and supporting evidence.
  • Log & Event Analysis: Analyze logs from endpoints, servers, network devices, and cloud environments.
  • Playbook Execution: Execute SOC SOPs and incident response playbooks consistently and accurately.
  • Case Documentation: Create and maintain investigation notes, incident timelines, and reports.
  • Threat Awareness: Stay informed on common attack techniques, indicators of compromise, and emerging threats.
  • Shift Operations: Participate in shift-based SOC operations, including possible night or weekend rotations.


Requirements:

  • Fresh graduates or professionals with up to 1–2 years of experience in cybersecurity, SOC, IT operations, or related roles.
  • Fundamental understanding of cybersecurity and SOC concepts (SIEM, incident response, alert triage).
  • Experience or familiarity with SIEM platforms - Google Security Operations (SecOps) is a strong plus; experience with other SIEMs (Splunk, QRadar, Elastic, Sentinel, etc.) is also acceptable.
  • Working knowledge of:
  • Networking fundamentals (TCP/IP, DNS, HTTP/S)
  • Operating systems (Windows and Linux.
  • Common threat types (phishing, malware, brute-force attacks, suspicious logins)
  • Willingness to work in shifts and operate in a 24/7 SOC environment.
  • Ability to follow procedures, think analytically, and communicate findings clearly.
  • Good command of Bahasa Indonesia and English (for alerts, documentation, and collaboration).


Nice to Have (Plus Points):

  • Hands-on experience with Google Security Operations (SecOps / Chronicle).
  • Familiarity with the MITRE ATT&CK framework.
  • Exposure to cloud environments (especially GCP, but AWS/Azure are also valuable).
  • Security certifications or ongoing study (Security+, Google Cloud Security, Blue Team labs, etc.).
  • Previous internship, SOC rotation, or hands-on lab experience in security monitoring.


Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search