You will monitor security alerts and events across SIEM and other security tools.
Responsibilities
- Perform real-time analysis of security threats, incidents, and anomalies.
- Investigate security events to determine severity, impact, and required response.
- Conduct threat hunting activities to identify potential vulnerabilities or suspicious patterns.
- Manage incident response processes from detection to resolution.
- Create incident reports, documentation, and recommendations for prevention.
Required Skills
- 12+ years of experience in cybersecurity or SOC operations.
- Strong hands-on experience with SIEM tools such as Splunk, QRadar, ArcSight, Sentinel.
- Deep understanding of network security, firewalls, IPS/IDS, endpoint security, and vulnerability management.
- Knowledge of common attack techniques, malware behavior, and threat analysis frameworks (MITRE ATT&CK, Cyber Kill Chain).
- Experience with incident response methodologies and digital forensics.
- Strong analytical and problem-solving abilities.
- Ability to work independently under pressure and manage multiple incident priorities.
- Excellent communication and documentation skills.