Responsibilities
- You will be the first point of contact for triaging security alerts and will engage more senior analysts and management as required
- Correlate data from SIEM, EDR, and firewall logs
- Perform basic log analysis and escalate suspicious activity
- Follow standard operating procedures and escalate issues or improvement opportunities as needed
- Map basic security incidents to MITRE ATT&CK tactics during documentation
- Identify and escalate issues related to data privacy
- Document incidents in ticketing systems
- Support endpoint and network monitoring activities
- Participate in shift handovers and daily SOC briefings
- Security Monitoring: Understands basic alert types and can triage low-level events
- Security Operations: Follows established SOC procedures and documents findings
- Incident Escalation: Recognizes when to escalate alerts to senior analysts
Qualifications
- 1+ years of experience in IT or security operations (internships or bootcamps acceptable)
- Basic understanding of networking protocols and operating systems
- Basic understanding of incident response phases
- Awareness of common indicators of compromise (IOCs)
- Familiarity with ticketing systems and escalation procedures
- Networking Basics: TCP/IP, DNS, DHCP, HTTP/S, ICMP
- Security Concepts: CIA triad, types of malware, phishing, brute force, DDoS
- Operating Systems: Basic Windows (Event Viewer, Task Manager), Linux (top, ps, netstat)
- Security Tools:
- SIEM: Splunk (basic search), IBM QRadar (offense monitoring)
- AV/EDR: Windows Defender, CrowdStrike
- Ticketing: ServiceNow, Jira
- Familiarity with SIEM tools and log analysis
- Cloud platforms: Basic AWS/Azure console navigation, understanding of cloud service types (IaaS, PaaS, SaaS)
- Basic understanding of containerization concepts (Docker, Kubernetes fundamentals)
- Strong attention to detail and documentation skills
- GenAI tools: ChatGPT or similar for threat research assistance, automated report summarization
- Foundational security certifications (e.g., Security+, Network+, CySA+, GSOC) or pursuing certification
Applicants must be authorized to work in the U.S.
We are an equal-opportunity employer. We do not discriminate in hiring or employment against any individual based on race, color, gender, national origin, ancestry, religion, physical or mental disability, age, veteran status, sexual orientation, gender identity or expression, marital status, pregnancy, citizenship, or any other factor protected by anti-discrimination laws.