Join our SOC team to monitor and investigate security alerts across SIEM, EDR, SOAR, firewalls & IDS/IPS. Perform triage, root-cause analysis, and incident response while tuning detection rules and reducing false positives. Ideal for someone with 2–3 yrs SOC/Cybersecurity experience, strong knowledge of Windows/Linux/AD, and familiarity with MITRE ATT&CK. Certs like CEH, Security+, eCIR are a plus. Own incidents end-to-end!
Key Responsibilities
Monitor security alerts and events from SIEM, EDR, SOAR, firewalls, IDS/IPS, and other security solutions in real time.
Perform alert triage and in-depth investigation to determine the root cause, scope, and impact of security incidents.
Develop, implement, and maintain new SIEM detection use cases and correlation rules to enhance threat detection capabilities.
Tune existing detection rules and reduce false positives while improving detection coverage.
Investigate endpoint, network, cloud, and identity-related security incidents using logs and security telemetry.
Validate indicators of compromise (IOCs) and leverage threat intelligence to support investigations.
Document investigation findings, root cause analysis, and response actions in the ticketing system.
Coordinate with infrastructure, network, and application teams during incident investigation and containment.
Stay up to date with the latest cyber threats, attacker techniques, vulnerabilities, and security technologies.
Requirements
Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related field.
1–3 years of experience in a Security Operations Center (SOC) or Cybersecurity role.
Job Qualifications
Hands-on experience with SIEM, SOAR, EDR, firewalls, IDS/IPS, endpoint security, and threat intelligence platforms.
Experience developing and tuning SIEM detection use cases, correlation rules, and security alerts.
Strong knowledge of Windows, Linux, Active Directory, network protocols, and common attack techniques.
Experience investigating malware infections, phishing, lateral movement, privilege escalation, and other security incidents.
Familiarity with MITRE ATT&CK, Cyber Kill Chain, and incident response methodologies.
Excellent analytical and problem-solving skills with the ability to investigate complex security events.
Strong communication and documentation skills.
Ability to work independently and take ownership of incidents from detection through resolution.
Security certifications such as eCIR, eCTHP, CEH, CompTIA Security+, or equivalent are preferred.
Fill out the form and upload your CV to submit your application.