Description
Job Summary:
Level 2 SOC Analyst to strengthen defense capabilities by performing alert analysis, incident management, and collaboration on improving threat detection.
Key Responsibilities:
1. Comprehensive analysis of security alerts and events
2. Monitoring and management of escalated incidents
3. Collaboration with teams to improve threat detection
At INSSIDE, we are seeking a **Level 2 SOC Analyst** to join our team and strengthen our defense capabilities.
**What will be your main responsibilities?:**
* Perform comprehensive analysis of security alerts and events.
* Correlate relevant alerts and events to identify threat patterns.
* Monitor and manage incidents escalated by the Level 1 team\.
* Provide technical support and guidance to Level 1 SOC analysts.
* Document all incidents in the appropriate system and maintain up-to-date records.
* Ensure proper handling of all received alerts.
* Track incidents from detection through resolution.
* Escalate verified incidents to the Incident Response (IR) team.
* Collaborate with other teams to develop use cases and improve threat detection.
* Participate in preparing monthly reports and presentations for clients and stakeholders.
* Facilitate shift handovers and ensure service continuity.
* Validate and oversee reports generated by Level 1 analysts\.
* Provide guidance and support to customers for incident remediation when necessary.
* Facilitate information handover processes during shift changes, ensuring relevant information is collected and disseminated per SOC requirements.
* Proactively engage in incident management without waiting for escalation or consultation from analysts.
* Collaborate in preparing monthly presentations for clients.
* Work closely with the SOC architecture and engineering team to refine and develop use cases.
* Contribute to ensuring synergy and alignment in assigned tasks.
**Requirements:**
* University student in Computer Science, Cybersecurity, or related fields.
* Minimum 2 years of experience in an SOC or information security environment.
* Solid knowledge of security tools and technologies (e.g., SIEM, IDS/IPS, firewalls, etc.).
* Relevant certifications (e.g., CompTIA Security\+, CEH, CISSP, etc.) are preferred.
* Intermediate/Advanced English.
* Availability for on-call duties.
**Work Modality**: Hybrid (2 days onsite at CABA offices \- 3 days remote).