Description
The Senior SOC Analyst takes the lead in monitoring, detecting, investigating, and responding to cybersecurity incidents within an organization. This role is vital in enhancing the organization's security posture, guiding junior analysts, and refining threat detection strategies.
Responsibilities
- Lead and oversee security event monitoring and threat detection using SIEM (Security Information and Event Management) systems.
- Conduct deep-dive investigations and forensic analysis of security incidents to determine impact and remediation steps.
- Respond to security incidents, coordinating with stakeholders and escalating complex threats as necessary.
- Develop, refine, and implement advanced incident response procedures and playbooks.
- Conduct threat intelligence research and proactive threat hunting activities.
- Mentor and guide junior SOC analysts, providing training and knowledge sharing.
- Collaborate with IT and security teams to improve security architecture and configurations.
- Document security incidents, findings, and recommendations for future mitigation and strategic improvements.
- Stay updated on the latest cybersecurity threats, trends, and industry's best practices.
- Assist in compliance audits and security assessments.
Skills and Qualifications
- Candidate must be a degree holder in Computer Science, Computer Engineering, Information Technology or equivalent qualifications
- 3-5 years of experience in cybersecurity, SOC operations, or a similar role.
- Advanced security certifications such as CISSP, OSCP, GCIH, GCIA, or equivalent.
- Expertise in SIEM tools, IDS/IPS, firewalls, and endpoint protection solutions.
- Strong knowledge of cybersecurity frameworks such as NIST, MITRE ATT&CK, or ISO 27001.
- Experience with malware analysis, threat intelligence, and digital forensics.
- Understanding of networking protocols, operating systems, and advanced security concepts.
- Strong analytical and problem-solving skills.
- Proficiency with scripting languages (Python, PowerShell, etc.) for automation.
- Experience with cloud security (AWS, Azure, Google Cloud).
- Familiarity with penetration testing and ethical hacking techniques.
- Excellent communication, leadership, and documentation abilities.
- Rotational shifts may be required to support 24/7 security monitoring.
- Ability to work in a fast-paced and high-pressure environment.