Search by job, company or skills

Security Analyst – L1( Information Security / Security Operations Center (SOC))

1-3 Years
SGD 3,000 - 4,500 per month
Quick Apply
  • Posted a month ago
  • Over 50 applicants have applied

Job Description

Role:Security Analyst – L1

Location: Singapore (Onsite)

Duration: 12 Months (Renewable) Contract

Department: Information Security / Security Operations Center (SOC)

Experience: 1–3 Years

About the Role

We are seeking a proactive and detail-oriented Security Analyst – L1 to provide 24x7 first-level security monitoring, alert triage, and incident handling across identity, endpoint, email, and cloud security platforms. The role focuses on early threat detection, incident ticket management, security event investigation, and timely escalation of confirmed threats to higher-level security teams.

The ideal candidate will have hands-on experience with Microsoft security technologies, endpoint protection solutions, identity and access management, Azure monitoring tools, and security operations processes. This position plays a critical role in maintaining organizational security posture through continuous monitoring, documentation, and adherence to incident response procedures.

Key Responsibilities

Security Monitoring & Alert Triage

  • Monitor security alerts and events across identity, endpoint, email, and cloud security platforms.
  • Review and triage security alerts based on defined operational procedures and escalation criteria.
  • Perform first-level investigation of suspicious activities and security anomalies.
  • Escalate confirmed threats and high-risk incidents to L2 Security Engineers for advanced analysis.

Identity & Access Security Monitoring

  • Monitor Microsoft Entra ID sign-in logs and authentication events.
  • Investigate suspicious login attempts, account lockouts, and abnormal authentication patterns.
  • Monitor Multi-Factor Authentication (MFA) failures and identify potential unauthorized access attempts.
  • Validate Conditional Access policy failures and document findings.

Email Security Operations

  • Monitor Exchange Online Protection alerts for spam, phishing, malware, and email-based threats.
  • Perform initial analysis of suspicious email activities.
  • Escalate high-risk email security incidents for further investigation.

Endpoint Security Monitoring

  • Monitor endpoint security alerts generated by Trend Micro Endpoint Security solutions.
  • Review malware detections, suspicious behaviors, and policy violation alerts.
  • Ensure proper ticket creation and escalation for critical endpoint incidents.

Privileged Access & Endpoint Privilege Monitoring

  • Monitor CyberArk Endpoint Privilege Manager (EPM) and Privileged Access Management (PAM) alerts.
  • Review privileged access activities and identify unusual privilege escalation attempts.
  • Escalate suspicious privileged account activities to security engineering teams.

Cloud Security Monitoring

  • Monitor Azure security dashboards, Azure Monitor, and Log Analytics workspaces.
  • Review cloud security alerts and identify potential threats or misconfigurations.
  • Assist in tracking security incidents affecting cloud resources and services.

Incident Management & Documentation

  • Create, update, and manage security incident tickets within ITSM platforms.
  • Ensure accurate incident classification, documentation, and evidence collection.
  • Maintain incident timelines, investigation notes, and closure records.
  • Adhere to defined SLAs for ticket acknowledgment, updates, and resolution tracking.

Operational Reporting & Compliance

  • Maintain daily security monitoring and shift activity reports.
  • Participate in shift handovers and ensure proper knowledge transfer.
  • Track certificate expiry notifications and communicate upcoming expirations to the L2 Security team.
  • Maintain audit-ready documentation and incident records.

Required Skills & Competencies

Identity & Access Management

  • Microsoft Entra ID (Azure AD) administration and monitoring.
  • Active Directory authentication monitoring.
  • Microsoft Multi-Factor Authentication (MFA).
  • Conditional Access monitoring and troubleshooting.

Email Security

  • Exchange Online Protection (EOP).
  • Spam, phishing, and malware alert analysis.

Endpoint & Privileged Access Security

  • Trend Micro Endpoint Security and Email Security.
  • CyberArk Endpoint Privilege Manager (EPM).
  • CyberArk Privileged Access Management (PAM).

Cloud Security & Monitoring

  • Azure Monitor.
  • Azure Log Analytics.
  • Microsoft Defender (Monitoring and Alert Review).
  • Azure security dashboards and monitoring tools.

Security Operations

  • Security event monitoring and alert triage.
  • Incident handling and escalation procedures.
  • Security ticket management and documentation.
  • Basic threat detection and analysis techniques.

PKI & Certificate Management

  • Basic understanding of Public Key Infrastructure (PKI).
  • Certificate lifecycle monitoring and expiry tracking.

IT Service Management

  • Experience with ITSM and ticketing platforms.
  • Incident tracking, escalation, and SLA management.

Preferred Qualifications

  • Microsoft Security, Azure, or Security Operations certifications.
  • Basic understanding of SIEM concepts and security monitoring workflows.
  • Familiarity with security frameworks such as ISO 27001, NIST, or CIS Controls.
  • Knowledge of phishing analysis, malware indicators, and identity-based attacks.
  • Experience working in a Security Operations Center (SOC) environment.

Key Performance Indicators (KPIs)

  • Security alert triage and response within defined SLA.
  • Accuracy of incident classification and escalation.
  • Timely creation and maintenance of security tickets.
  • Quality of incident documentation and closure notes.
  • Shift handover completeness and operational reporting accuracy.
  • Compliance with security monitoring procedures and escalation standards.

What Success Looks Like

  • Timely detection and escalation of security threats.
  • Consistent monitoring coverage across all security platforms.
  • Accurate incident documentation and reporting.
  • High SLA adherence for security event handling.
  • Strong collaboration with L2 Security Engineers and Infrastructure Teams.
  • Continuous improvement in threat detection and operational effectiveness.

 

 

Interested candidates can connect on +6586533349 (WhatsApp chat only)

More Info

Job Type:
Function:

Job ID: 149249077

Beware of Scammers

We don’t charge money for job offers