Tech Stack
AWSAzureCloudCyber SecurityPythonServiceNowSplunk
About the role
- Monitor security event logs, network traffic, and system alerts to identify potential security threats
- Analyze and triage security alerts to determine severity and impact
- Investigate security incidents, including root cause analysis and recommendation of remediation steps
- Develop and implement incident response plans and procedures
- Collaborate with cross-functional teams to address security concerns and implement security measures
- Stay up-to-date with emerging threats, technologies, and industry best practices
- Provide security awareness training and education to employees
- Participate in the development and maintenance of security policies, procedures, and standards
Requirements
- Bachelor/Master Degree in Information Security, Computer Science or related field
- At least 6+ years of experience in a SOC or Cybersecurity Analyst or similar role
- Experience with threat analysis and incident response
- Excellent analytical and problem-solving skills
- Strong communication and collaboration skills specifically in English
- Relevant certifications (e.g., CompTIA Security+, CISSP, CEH)
- SIEM (Security Information and Event Management) systems: Such as Splunk, ELK Stack, or IBM QRadar
- Threat intelligence platforms: Like ThreatQuotient, Anomali, or MISP
- Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS): Snort, Suricata, or Cisco IPS
- Firewall and network security management: Check Point, Cisco ASA, or Fortinet
- Endpoint security solutions: Endpoint Detection and Response (EDR) tools, e.g., Carbon Black, CrowdStrike, or McAfee
- Vulnerability management and scanning tools: Nessus, OpenVAS, or Qualys
- Incident response and forensic analysis tools: EnCase, FTK, or Volatility
- Security orchestration and automation tools: Phantom, Demisto, or Swimlane
- Cloud security and monitoring tools: AWS Security Hub, Google Cloud Security Command Center, or Microsoft Azure Security Center
- Scripting languages and automation tools: Python, PowerShell, or Bash
- Ticketing and incident management systems: JIRA, ServiceNow, or BMC Helix
- Network monitoring and traffic analysis tools: Wireshark, Tcpdump, or Bro
- Experience with Github Actions, Gitlab CI or other CI/CD systems
- Nice to Have: Experience with cloud security and DevOps
- Nice to Have: Knowledge of compliance frameworks (e.g., HIPAA, PCI-DSS)
- Nice to Have: Programming skills (e.g., Python, PowerShell)
- Nice to Have: Experience with security automation and orchestration tools