5+ years in IT security analysis or a similar role
Experience with alert analysis including phishing and malware
Proficiency in event correlation using SIEM or EDR tools
Strong documentation skills for investigations and findings
Demonstrated ability to coach and support junior analysts
Responsibilities
Investigate and qualify escalated alerts from level 1 SOC
Correlate events across various platforms for complete visibility
Enrich alerts with logs and threat intelligence for deeper insights
Determine severity and impact of incidents and recommend actions
Initiate initial mitigation and containment measures as necessary
Document all investigation steps, findings, and responses
Coach level 1 SOC analysts on complex investigations
Benefits
Health group insurance coverage
Opportunities for professional development
Flexible working environment
Access to approved AI and automation tools for enhanced productivity
Full Job Description
Job Description Overview:
The client is looking for an IT security analyst for its SOC, positioned at level 2: alerts reach this person already escalated by level 1, and the person in turn acts as the technical escalation point for those analysts.
The work centres on investigation: qualifying phishing, account compromise, malware or lateral movement cases, correlating events across several platforms, then enriching them with logs, indicators of compromise and threat intelligence.
The person determines verdict, severity and impact, then recommends or initiates first measures according to established processes, with incident response remaining initial and carried out with other teams.
The form title specifies no level, while the full set of responsibilities describes a level 2 role.
The Talents and qualifications section is empty: no degree, certification, language or named tool is required, so assessment rests entirely on the activity profile.
Target candidate: a QA professional with at least 10 years in IT, including 5 years in testing, who has coordinated testing within agile teams and uses JIRA, XRAY, Cypress and Playwright in recent mandates.
Group insurance exposure or an integration project will set apart otherwise equal candidates.
Requirements
Required:
Analysis and qualification of escalated alerts (phishing, account compromise, malware, lateral movement)