
SOC Analyst – Level 1
IPV7
full-time
Posted on:
Location Type: Remote
Location: Brasil
Visit company websiteExplore more
About the role
- Perform active monitoring of security events using SIEM platforms (such as Wazuh, Splunk, Microsoft Sentinel, or QRadar) and endpoint protection tools (EDR/XDR).
- Analyze and triage alerts generated by security tools, identifying potential incidents and reducing false positives.
- Execute initial containment actions according to defined security playbooks (e.g., host isolation or credential resets).
- Log and document incidents and activities in ITSM ticketing systems, ensuring traceability and organized information.
- Perform structured escalation of more complex incidents to N2 or N3 teams, ensuring the full investigation context is handed over.
- Track operational detection and incident response metrics and indicators.
Requirements
- Knowledge of networking fundamentals and protocols such as the OSI model, TCP/IP, and DNS.
- Experience or familiarity with network traffic analysis tools (Wireshark or Tcpdump).
- Operational knowledge of Windows and Linux environments, including basic terminal/CLI navigation.
- Basic understanding of security solutions such as firewalls, IPS/IDS, WAF, and antivirus/EDR.
- Familiarity with cyber threat concepts like phishing, malware, brute-force attacks, and ransomware.
- Bachelor’s degree completed or in progress in Cyber Defense, Computer Science, Engineering, Networks, or related fields.
- Entry-level information security certifications such as CompTIA Security+, Cisco CyberOps Associate, Microsoft SC-900, or similar.
- Practical knowledge of the MITRE ATT&CK framework.
- Previous experience in technical support, IT infrastructure, or systems monitoring environments.
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
SIEMEDRXDRnetwork traffic analysisWindowsLinuxfirewallsIPSIDSMITRE ATT&CK
Soft Skills
incident analysisalert triagedocumentationescalationcommunication
Certifications
CompTIA Security+Cisco CyberOps AssociateMicrosoft SC-900