SOC Analyst - Remote / Telecommute
Cynet Systems
Frisco, TX
Remote
Full-time
Job Description :
- Should have experience in SIEM-Client analysis of notable events.
- Monitor Client Console & Dashboards and provide response to the reported incidents.
- Perform initial analysis for known issues and provide the appropriate recommendations for closure.
- Monitor & Reporting of Client components health and take necessary action in case of any observed issue.
- Provide notification and communication with Incident management and respective application teams upon threat detection.
- Should have experience in investigation of Phishing, Malware related incidents.
- Should have knowledge of Azure cloud and cloud security.
- Should have knowledge of Firewall, IPS, Proxy and other infrastructure security.
- Should have knowledge of SOAR Automation platform.
- Should have knowledge of Threat Client and its integration.
- Daily report preparation on the number of incidents detected, closed, in progresses, open security issues.
- Maintain post incident documentation about all the actions taken, root cause, controls implemented.
- Perform analysis on the reported incidents, determine the root cause, recommend the appropriate solution.
- Monitor and review the L1 / L2 activities.
- Should provide real time situational awareness to customer's stakeholders.
- Develop and implement processes for interfacing with operational teams and other supporting teams.
- Triage Critical incidents based on an agreed threat matrix.
- Should have hands-on experience on Microsoft Defender EDR.
- Triage incident based on Defender EDR timeline observation.
- Design, create and customize the dashboards as per customer requirements.
- The required candidate must be able to understand and communicate clearly to required stakeholders.
Secondary Skills :
- Should be able understand false positives and false negatives related to Security Events.
- Presentation and articulation skill.
- Good communication skill with internal and external customers.
15 days ago