D
Senior SOC Analyst
D
Senior SOC Analyst
dacta sg pte. ltd.- Posted 2 hours ago
- Be among the first 10 applicants
Job Description
SUMMARY
DACTA is looking for a highly motivated and experienced Senior SOC Analyst to join our Security Operations Centre (SOC) team. The Senior SOC Analyst will be responsible for monitoring, investigating, analysing, and responding to complex security incidents across various security platforms and technologies, while also managing and leading a small team of SOC Analysts.
RESPONSIBILITIES
- Continuously monitor and analyse security events and alerts from various sources, including SIEM, EDR/XDR, firewalls, IDS/IPS, endpoint security, network security, and other security infrastructure.
- Investigate and respond to security incidents, including complex and high-severity cybersecurity events.
- Conduct detailed analysis of security events, logs, network traffic, endpoint activities, and other relevant security data to determine the severity, impact, scope, and root cause of incidents.
- Perform advanced incident investigation and determine appropriate containment, eradication, recovery, and remediation actions.
- Conduct threat hunting activities to proactively identify suspicious activities, indicators of compromise (IOCs), attacker behaviours, and potential security threats.
- Develop and utilize threat-hunting queries and techniques to identify emerging threats and malicious activities.
- Analyse and correlate information from multiple security sources to identify attack patterns, anomalies, and potential security incidents.
- Perform analysis of malware, suspicious files, URLs, domains, IP addresses, and other indicators of compromise where required.
- Analyse threat intelligence and security research to identify emerging cybersecurity threats, vulnerabilities, attack techniques, and indicators that may affect the organisation or its customers.
- Apply recognised cybersecurity frameworks and methodologies, including MITRE ATT&CK, during security investigations and threat analysis.
- Develop, maintain, and improve SIEM correlation rules, detection rules, dashboards, alerts, and security monitoring use cases.
- Assist in tuning and optimizing security tools and detection mechanisms to improve detection accuracy, reduce false positives, and enhance overall SOC capabilities.
- Identify gaps in existing security monitoring and recommend improvements to security tools, processes, procedures, and detection capabilities.
- Coordinate with IT, network, infrastructure, application, and other technical teams to facilitate timely investigation, containment, and remediation of security incidents.
- Participate in the management and response of major or critical security incidents and provide technical recommendations to relevant stakeholders.
- Conduct root cause analysis and post-incident reviews and provide recommendations to prevent recurrence of security incidents.
- Prepare and maintain detailed incident reports, investigation findings, root cause analysis, remediation recommendations, and other security documentation.
- Develop and maintain incident response procedures, playbooks, investigation guides, and SOC operational documentation.
- Provide technical guidance and knowledge sharing to SOC team members to improve investigation and incident-handling capabilities.
- Participate in regular SOC meetings, cybersecurity training, tabletop exercises, knowledge-sharing sessions, and continuous improvement initiatives.
- Maintain up-to-date knowledge of cybersecurity threats, vulnerabilities, attack techniques, security technologies, and industry best practices.
- Perform other cybersecurity and SOC-related duties and responsibilities as assigned by management.
- Manage and lead a small team of SOC Analysts to ensure effective day-to-day SOC operations and timely handling of security incidents.
REQUIREMENTS
- Bachelor's degree in Cybersecurity, InformationTechnology, Computer Science, Information Security, or a related field, or equivalent professional experience.
- 5 years or more of relevant experience in SOC operations, cybersecurity, security monitoring, incident response, or a related cybersecurity environment.
- Strong hands-on experience in security monitoring, incident investigation, and incident response, SIEM platforms, such as Splunk, ArcSight, QRadar, Microsoft Sentinel, or similar technologies.
More Info
Key Skills
XDR
Detection rules
SIEM correlation rules
Security monitoring use cases
Alerts
