Monitor and analyse security alerts through the SIEM platform.
Conduct investigation of alerts, perform analysis and correlation of events from various sources.
Collaborate with teams across functions to ensure prompt and efficient alert investigation and incident response.
Follow established policies and procedures to escalate security incidents.
Keep precise records of incident response activities.
Drive a continuous effort to improve the SOC process.
Participate in the distributed 24x7 operations and on-call duties.
Requirements:
Bachelor's degree or higher in Computer Science, Information Security, or a related field
Experience in Security Operations, Threat Intelligence, or Incident Response
Strong practical experience with Security Information and Event Management (SIEM) platforms
Comprehensive understanding of threats, vulnerabilities, exploits, defences, security principles, and policies.
Proficient in security best practices and key security technologies, including but not limited to: EDR, HIDS, WAF, DLP, NIDS, NIPS
In-depth knowledge of Linux and Windows administration, including system authentication , patch deployment , system configuration and security controls