- Posted 8 hours ago
- Be among the first 10 applicants
Job Description
Job Description:
- Analyze and investigate security alerts escalated from SOC L1.
- Perform deep incident investigation (malware, phishing, intrusion, unauthorized access).
- Correlate logs from SIEM, firewall, IDS/IPS, endpoints, and servers to identify root cause and impact.
- Identify Indicators of Compromise (IOC) and support incident scoping.
- Execute initial incident response actions such as isolation, blocking IPs, or disabling accounts.
- Tune SIEM rules and reduce false positives.
- Conduct threat hunting and support vulnerability analysis.
- Create incident reports, RCA, and security documentation.
- Use security tools such as SIEM, firewall, EDR, and ticketing systems (Jira, TheHive).
Qualifications:
- Bachelor's degree in IT, Cybersecurity, Computer Science, or related fields.
- Experience 2 to 4 years working in cybersecurity or IT security roles / at least 2 year as a SOC Level 1 Analyst or similar role.
- Good understanding of security tools: SIEM (Qradar), EDR, antivirus, firewalls, IDS/IPS, etc.
- Able to analyze logs from networks, servers, and endpoints.
- Know basic networking and how operating systems (Windows/Linux) work.
- Understand common attack methods and frameworks like MITRE ATT&CK.
- Have information security certification (CompTIA Security+, ISC2 CC, CEH, ect) is a plus.
More Info
Key Skills
vulnerability analysis
TheHive
Windows
