Search Jobs

Search by job, company or skills

Junior SOC Analyst SIEM (Google SecOps)

Junior SOC Analyst SIEM (Google SecOps)

pillar
Fresher
  • Posted 4 hours ago
  • Be among the first 10 applicants

Job Description

About Us:

PILLAR AI (formerly Ringkas) — the AI-native sales infrastructure for financial institutions, loan origination, built on four years of live, real-world data. We're not prototyping. We're scaling a system already proven across 33 bank partners and 50+ cities. What started in Asia is now expanding across the GCC through our partnership with ROSHN Group in Saudi Arabia and others.

Role Summary:

We are hiring a Junior SOC Analyst to monitor, triage and escalate security events in Google Security Operations (SecOps, formerly Chronicle) as part of a 24/7 security monitoring service. You will be one of the people who keeps eyes on our Google Cloud (GCP) environment around the clock, including nights, weekends and public holidays.

Key Responsibilities:

Monitoring and triage (Google SecOps SIEM)

  • Watch Google SecOps alert queues, dashboards and detections in real time during your shift.
  • Triage alerts from YARA-L detection rules and curated detections; classify each as true positive, false positive or benign.
  • Investigate events with UDM search, entity/asset views and raw log search to build a timeline.
  • Prioritise security events such as Cloud Armor/WAF blocks, IAM role and service-account key changes, access revocations, unauthorised access attempts, and public exposure of data or resources.
  • Enrich alerts with threat intelligence (VirusTotal, Google Threat Intelligence, IP/domain reputation).

Incident handling and escalation

  • Open, document and track cases in Google SecOps SOAR, following the Incident Response Plan and playbooks.
  • Escalate confirmed or suspected incidents to the SOC Lead / L2 within the defined SLA, and send client notifications through the approved channels.
  • Run first-response playbook steps under guidance: disable accounts, revoke sessions or keys, block IPs in Cloud Armor.

Log sources and detection hygiene

  • Check that log ingestion is healthy (Cloud Audit Logs, Cloud Armor, VPC Flow Logs, Entra ID sign-in logs, endpoints) and raise tickets for gaps or parser errors.
  • Flag noisy rules and suggest tuning; help draft new detections with senior analysts.

Reporting and handover

  • Write a shift handover at the end of every shift: open cases, actions taken, pending escalations.
  • Contribute evidence to the monthly security-incident summary (security incidents only: breach, unauthorised access, revocation, exposure).
  • Keep SOPs, runbooks and the knowledge base up to date.

Requirements:

  • Diploma or bachelor's degree in Computer Science, Information Security, IT or a related field, or equivalent hands-on experience.
  • 0–2 years in a SOC, NOC, IT support or security role; fresh graduates with strong lab or internship experience are welcome.
  • Hands-on exposure to a SIEM, with Google SecOps (Chronicle) preferred: UDM search, reading alerts, basic YARA-L rule logic.
  • Working knowledge of networking (TCP/IP, DNS, HTTP/S, firewalls, WAF) and common attack types (phishing, brute force, credential stuffing, privilege escalation).
  • Basic familiarity with Google Cloud: IAM, service accounts, Cloud Audit Logs, Cloud Armor.
  • Understanding of identity and access concepts: SSO, MFA, Microsoft Entra ID sign-in logs.
  • Familiarity with MITRE ATT&CK and the incident response lifecycle (NIST SP 800-61).
  • Clear written English for tickets, handovers and client notifications; Bahasa Indonesia for internal communication.
  • Willing and able to work rotating 24/7 shifts, including nights, weekends, holidays and overtime.
  • Willing and able to secured google security officer certification
  • Calm under pressure, detail-oriented, and disciplined about following SOPs.

Nice To Have:

  • Certifications: Google Cloud Professional Security Operations Engineer, CompTIA Security+ or CySA+, Google Cybersecurity Certificate, EC-Council CSA, or Blue Team Level 1 (BTL1).
  • Experience with Google SecOps SOAR playbooks or another SOAR tool.
  • Exposure to other SIEMs (Splunk, Microsoft Sentinel, IBM QRadar).
  • Basic scripting in Python, Bash or PowerShell to automate lookups.
  • Awareness of ISO 27001, SOC 2, or Saudi NCA ECC / Indonesian OJK and UU PDP requirements.
  • Home lab, CTF or TryHackMe / LetsDefend SOC path experience.

Item

Detail

More Info

Job Type:
Industry:
Employment Type:

Key Skills

UDM search

Cloud Armor

Cloud Audit Logs

YARA-L

NIST SP 800-61

Google SecOps

About Company