Job Description

- Continuously monitor SIEM/SOAR/EDR/IDS dashboards and alerts
- Verify log source health, time synchronization, and parsing quality
- Initial enrichment (user/asset/geo/history), suppress false positives, assign severity and priority
- Quickly check IOCs against TI sources
- Open/update tickets in ITSM tools (ServiceNow/Jira), record evidence and timelines per SLA
- Escalate to Tier 2/IR/SOC Lead per the escalation matrix and severity levels
- Coordinate with infrastructure/network/email teams for urgent actions
- Track and report MTTA/MTTD, false-positive rate, and ticket quality/completeness
- Prepare concise summaries of notable incidents for management
- Start-of-shift review, update open items, risks, and dependencies
- End-of-shift written/oral handover detailing status and next actions for each ticket

Requirements
- Experience: 1–2 years in SOC/security helpdesk or a relevant internship
- SIEM: one of Splunk, QRadar, Microsoft Sentinel, Elastic SIEM
- EDR: one of Microsoft Defender, CrowdStrike, SentinelOne, Trellix , Kaspersky
- SOAR and ITSM: familiarity with Splunk SOAR/XSOAR/Sentinel SOAR and ServiceNow/Jira
- TI and analysis: Virus Total, OTX/MISP, Wireshark; querying with KQL/SPL/QL; regex
- Networking: TCP/IP, DNS, HTTP(S), SMTP, VPN; NAT/Proxy/Firewall/IDS/IPS/WAF/DLP
- Operating systems and domain: Windows/Linux, Active Directory, email and M365/Exchange
- Frameworks and models: MITRE ATT&CK, CIA triad, incident lifecycle, ITIL Incident Management
- Ability to work in rotating shifts (12/24 - 12/48 schedule), including weekends/holidays as needed

Employment Type

  • Full Time

Details

To see more jobs that fit your career