SOC 2 Analyst

Posted 56ds ago

Employment Information

Industry
Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Tier 2/3 SOC Analyst investigating security incidents and using threat intelligence for APAC. Collaborating with stakeholders to monitor systems and responding to security threats.

Responsibilities:

  • Investigating security incidents and determining their root causes
  • Reviewing incidents escalated by Tier 1 analysts
  • Using threat intelligence to assess alerts, threats and potential incidents in depth
  • Monitoring systems and events across different operating systems (Windows, macOS, Linux)

Requirements:

  • 5+ years recent experience as Tier 2 or 3 analyst at a large organization
  • Strong, demonstrated SIEM and data correlation experience
  • Demonstrated experience designing new SOC use cases and working with vendor on implementing new use cases
  • Experience designing and implementing runbooks and use cases to mitigate security incidents
  • Experience designing Incident Response plan, including alert definition, runbooks, escalation, etc.
  • Extensive experience reviewing and managing alerts in Microsoft Defender, Splunk and or Crowdstrike
  • Experience conducting hunts across disparate data sets, to include host data, vulnerability data, threat data, network data, active directory data, among others to identify threats
  • Experience leading timely security operations response efforts in collaboration with stakeholders
  • Experience documenting incident response communications for technical and management audiences
  • Experience setting up alert rules and effective alert management
  • Demonstrated ability to create runbooks and conducting investigations with key application, IT Infra and other stakeholders
  • Experience designing custom SOC SIEM use cases in Defender, Splunk and CRWD
  • Experience conducting forensic work investigations
  • Problem solver
  • Curious
  • Analytical, qualitative and quantitative abilities
  • Adaptive to dynamic environment
  • Strong security operations documentation abilities.