Role:
Security Operations Center (SOC) Analyst – Level 1
Experience:2 to 4 years in SOC
Key Skills:
- SIEM Monitoring using:
- Splunk Enterprise
- IBM QRadar
- MSS (Managed Security Services) operations
- Security event monitoring and alert analysis
- Incident triage and escalation
- Log analysis and correlation
- Basic networking knowledge (TCP/IP, DNS, HTTP, VPN)
- Understanding of cyber threats and attack techniques
- Ticketing tools (ServiceNow/JIRA/Remedy)
- Basic knowledge of:
- Windows/Linux logs
- Firewall alerts
- IDS/IPS
- Endpoint security
Responsibilities:
- Monitor security alerts and events in SIEM tools
- Analyze and investigate suspicious activities
- Perform initial incident triage and classification
- Escalate critical incidents to L2/L3 teams
- Create and manage incident tickets
- Follow SOC playbooks and SOPs
- Generate daily/weekly security reports
- Support MSS clients in 24x7 SOC environment
- Maintain SLA compliance
Preferred Certifications:
- CompTIA Security+
- CEH
- Splunk Fundamentals
- IBM QRadar Fundamentals
- SC-200 (Microsoft Security Operations Analyst)
Shift Requirement:
- Rotational shifts / 24x7 SOC environment