Role Summary
The analyst will work in the Cybersecurity Operations Center (CSOC) performing advanced threat triage, incident response, and vulnerability analysis. They’ll be the first line of defense for monitoring SIEM, EDR, IDS/IPS, and cloud security platforms, escalating confirmed threats, and documenting investigations.
Essential Functions
Monitor & triage alerts from SIEM, EDR, IDS/IPS, firewalls, email/cloud security.
Investigate suspicious activity, phishing, malware, anomalous behavior.
Escalate confirmed threats to IR/Threat Hunting/SOC Engineering.
Document findings in ticketing/case management systems.
Assist with containment, eradication, and recovery.
Tune alerts, refine processes, integrate threat intel.
Perform vulnerability assessments & remediation prioritization.
Research emerging threats & attack techniques.
Skills & Knowledge
SOC operations, incident triage, escalation.
SIEM (Sentinel, Splunk, QRadar, etc.), EDR (CrowdStrike, SentinelOne, Defender).
IDS/IPS (Trellix/FireEye, Corelight).
Threat intel (VirusTotal, Cisco Talos, Recorded Future).
Vulnerability tools (Tenable, Qualys, Rapid7).
Email security (Proofpoint, IronPort, Abnormal.ai).
Cloud security (Wiz, Sysdig, Prisma, Zscaler).
Familiarity with MITRE ATT&CK, NIST frameworks, PICERL.
Query languages (KQL, SPL, Lucene) & scripting (Python, PowerShell, Bash).
Minimum Requirements
3+ years in cybersecurity ops, monitoring, incident response, threat detection, investigations.
Hands-on with SIEM, EDR, IDS/IPS, threat intel, vulnerability management.
Experience documenting investigations & applying frameworks.
Preferred
5+ years experience (strongly preferred).
Bachelor’s in Cybersecurity/CS/IS or related.
Certifications: Security+, GCIH, GCIA, CSA, SC-200, or similar.