Job Description: SOC AnalystPosition Title SOC Analyst (Security Operations Center Analyst)
Job Summary We are seeking a skilled SOC Analyst to monitor, detect, investigate, and respond to cybersecurity threats across enterprise environments. The ideal candidate will analyze security alerts, perform incident investigations, identify potential threats, and support incident response activities to protect organizational systems, networks, and data.
Key Responsibilities - Monitor security alerts and events from SIEM, EDR, IDS/IPS, and other security monitoring platforms.
- Analyze and investigate security incidents, suspicious activities, and potential threats.
- Perform alert triage, escalation, and incident classification based on severity and impact.
- Conduct log analysis across endpoints, servers, applications, and network devices.
- Identify indicators of compromise (IOCs) and indicators of attack (IOAs).
- Perform threat hunting activities to detect advanced threats.
- Support malware analysis and suspicious file investigations.
- Investigate phishing emails, credential-based attacks, and unauthorized access attempts.
- Create and maintain incident response documentation and playbooks.
- Escalate critical security incidents to senior analysts and incident response teams.
- Generate security reports, dashboards, and incident summaries.
- Stay updated on emerging threats, vulnerabilities, and attacker techniques.
Required Technical Skills - Hands-on experience with SIEM platforms such as:
- Splunk
- Microsoft Sentinel
- IBM QRadar
- ArcSight
- LogRhythm
- Knowledge of security monitoring tools:
- EDR/XDR solutions
- IDS/IPS
- Firewalls
- Antivirus and endpoint security tools
- Understanding of networking concepts:
- TCP/IP
- DNS
- HTTP/HTTPS
- VPN
- Firewall rules
- Knowledge of operating systems:
- Windows security concepts
- Linux fundamentals
- Understanding of cybersecurity concepts:
- Incident response lifecycle
- Threat intelligence
- MITRE Telecommunication&CK framework
- Vulnerability management
- Malware analysis basics
- Ability to analyze logs from:
- Windows Event Logs
- Linux system logs
- Firewall logs
- Proxy logs
- Authentication logs
Preferred Tools & Technologies - SIEM: Splunk, Sentinel, QRadar, ArcSight
- EDR: CrowdStrike, Microsoft Defender, SentinelOne
- Network Security: Palo Alto, Fortinet, Cisco security products
- Threat Intelligence Platforms
- Ticketing systems: ServiceNow, Jira
Certifications (Preferred) - CompTIA Security+
- CompTIA CySA+
- Certified Ethical Hacker (CEH)
- GIAC Security Operations (GSEC)
- Certified SOC Analyst (CSA)
- Microsoft Security Operations Analyst (SC-200)
Education & Experience - Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field preferred.
- Experience in SOC operations, security monitoring, incident response, or threat analysis.
- Knowledge of cybersecurity frameworks and best practices.
- Ability to work in a 24x7 SOC environment (where applicable).
Soft Skills - Strong analytical and problem-solving skills.
- Ability to prioritize and handle multiple security alerts.
- Good written and verbal communication skills.
- Ability to document incidents clearly.
- Strong attention to detail and investigative mindset.
Key Deliverables - Timely alert investigation and resolution.
- Incident reports and escalation documentation.
- Threat intelligence updates.
- Security monitoring improvements.
- Root cause analysis reports.
Role Type Full-time / Contract
Department Cybersecurity / Security Operations Center (SOC)