SOC Detection Analyst
6 months | |
Total Yrs. of Experience |
6+ years |
Relevant Yrs. of experience |
4+ years |
Detailed JD (Roles and Responsibilities) |
Responsibilities: |
Advanced Security Event Analysis and Triage: | |
Conduct in-depth analysis of complex and escalated security alerts and events from various security tools (SIEM, IDS/IPS, EDR, etc.). | |
Correlate data from multiple sources to identify and validate potential security incidents with high accuracy. | |
Perform advanced triage to determine the scope, severity, and potential impact of security events. | |
Document analysis findings clearly and concisely, providing actionable intelligence for incident response. | |
Detection Rule Development and Optimization: | |
Develop, implement, and fine-tune correlation rules, alerts, and dashboards within the SIEM platform to improve detection capabilities and reduce false positives. | |
Analyze existing detection logic and recommend improvements based on threat intelligence, incident trends, and best practices. | |
Stay current with emerging threats and attack techniques to proactively develop new detection strategies. | |
Threat Intelligence Integration: | |
Leverage threat intelligence feeds and platforms to enrich security event analysis and identify potential threats targeting the organization. | |
Correlate threat intelligence with internal security data to proactively identify indicators of compromise (IOCs). | |
Contribute to the development of threat profiles and attack scenarios relevant to the organization. | |
Incident Escalation and Collaboration: | |
Serve as a point of escalation for complex or high-severity security events. | |
Collaborate effectively with incident responders, threat hunters, and other security teams to provide critical context and analysis during incident handling. | |
Provide technical guidance and support to junior analysts during incident triage and analysis. | |
Security Tooling and Technology Expertise: | |
Maintain a strong understanding of the organization's security infrastructure and the capabilities of various security tools. | |
Troubleshoot issues with security monitoring tools and contribute to their optimization. | |
Evaluate and recommend new security technologies or enhancements to existing tools to improve detection capabilities. | |
Development of Knowledge and Procedures: | |
Contribute to the development and maintenance of SOC knowledge base articles, standard operating procedures (SOPs), and playbooks related to detection and analysis. | |
Share knowledge and best practices with other SOC analysts through training and mentorship. | |
Proactive Threat Hunting Support: | |
Collaborate with threat hunters by providing insights from security event analysis and identifying potential areas of focus for proactive investigations. | |
Assist in the development and execution of threat hunting methodologies. | |
Reporting and Metrics: | |
Contribute to the development of key performance indicators (KPIs) and metrics related to detection effectiveness. | |
Prepare reports on detection trends, alert volumes, and analysis findings. |