SOC L1/Tech Support
SOC L1/Tech Support
Solaire Resort & Casino0-2 Years
- Posted 8 hours ago
- Be among the first 10 applicants
Job Description
Duties and Responsibilities
- Monitor SIEM dashboards, alerts, and security events across network, endpoint, cloud, and application log sources on a 24/7 shift rotation.
- Perform initial triage, classification, and prioritization of security alerts following documented playbooks and runbooks.
- Escalate validated or complex incidents to SOC L2 with complete and accurate documentation of findings and actions taken.
- Record all alerts, investigations, and response actions in the case management/ticketing system.
- Perform routine health checks on security monitoring tools and report gaps in log sources or detection coverage.
- Triage phishing reports and user-reported security concerns, executing first-response steps per playbook.
- Execute containment actions as directed by SOC L2 or the incident lead during active incidents.
- Contribute tuning recommendations to reduce false positives and improve alert quality.
- Maintain complete shift-handover logs to ensure continuity of monitoring between shifts.
- Mean time to acknowledge (MTTA) alerts within defined SLAs.
- Alert triage accuracy and quality of escalations to SOC L2.
- Percentage of alerts and cases handled within SLA.
- Completeness and quality of case documentation and shift handovers.
- False-positive identification and tuning recommendations submitted.
- Education: Bachelor's degree in computer science, information technology, or a related field, or equivalent practical experience.
- Experience: 0–2 years in security operations, IT support, or network/system administration; prior SOC or managed security service experience preferred. Must be willing to work on a 24/7 shift rotation.
- Skills & Knowledge: Foundational knowledge of networking (TCP/IP, DNS, HTTP), Windows and Linux operating systems, and common attack techniques (MITRE ATT&CK); familiarity with SIEM platforms (Splunk, Microsoft Sentinel, QRadar, or similar) and ticketing tools.
- Certifications (good to have): CompTIA Security+, CompTIA CySA+, or Microsoft SC-200 preferred.
