Role Proficiency:
Serve as the first point of contact for cyber security incidents escalations and investigation. Work with different teams to improve service provided by SOC to clients around the globe.
Outcomes:
Measures of Outcomes:
Outputs Expected:
Incident Advance investigations :
Review and improve work and processes in L1 team:
Improve SOC detection and monitoring service :
Skill Examples:
SIEM IPS WAF etcFast self-learningGood analytic skillsGood soft skills (Verbal and writing)Presentation skill (Verbal)Programming languages such as C C# Python Perl Java PHP and Ruby on Rails
Knowledge Examples:
Knowledge Examples
Additional Comments:
L3 SOC Analyst Experience :13 years (out of this, minimum 7 years' experience on proposed CSOC solution) - Experience with SIEM vendors such as QRadar, Sentinel, Splunk - Incident response and threat hunting expertise - Strong knowledge of attack patterns, Tools, Techniques, and Procedures (TTPs) - Experience in writing procedures, runbooks, and playbooks - Strong analytical and problem-solving skills - Hands-on experience with system logs, network traffic analysis, and security tools - Proficiency in identifying Indicators of Compromise (IOCs) and Advanced Persistent Threats (APTs) Good-to-Have Skills: - Experience setting up SIEM solutions and troubleshooting connectivity issues - Familiarity with security frameworks and best practices - Ability to collaborate with IT and security teams effectively Responsibilities: - Act as an escalation point for high and critical severity security incidents - Conduct in-depth investigations to assess impact and understand the extent of compromise - Analyze attack patterns and provide recommendations for security improvements - Perform proactive threat hunting and log analysis to detect potential threats - Provide guidance on mitigating risks and improving security hygiene - Identify gaps in security processes and propose enhancements - Ensure end-to-end management of security incidents - Document and update incident response processes and define future outcomes - Participate in war room discussions, team meetings, and executive briefings - Train team members on security tools and incident resolution procedures
Soc,Network Security,Cyber Security
Keyskills: c# sentinel python analytical cyber security network security soc ip verbal communication presentation skills information security vulnerability management siem vulnerability assessment incident response qradar cyber security java ruby rails threat hunting splunk php perl