SOC Analyst
פורסם לפני 27 ימים · 80 מועמדים
התפקיד במילים פשוטות
התפקיד כולל ניטור וניתוח שוטף של התראות אבטחה בזמן אמת באמצעות מערכות SIEM, SOAR ו-EDR במסגרת משמרות 24/7. ביומיום, העובד מבצע תחקור ראשוני לאירועי אבטחה, ניתוח לוגים במערכות שונות והסלמה של מקרים מורכבים לצוותים בכירים.
- At least 1 year of hands-on experience working with SIEM & SOAR systems
- Strong familiarity with EDR, Firewalls, Proxy, and WAF solutions
- Solid understanding of networking protocols (TCP/IP, DNS, HTTP/HTTPS)
- Good working knowledge of Windows and Linux operating systems
- Proven ability to analyze security logs and investigate anomalies
- Hands-on experience with Splunk, Microsoft Sentinel, or IBM QRadar
- Experience with Cortex XSOAR (or equivalent SOAR platforms)
- Experience with CrowdStrike Falcon, SentinelOne, or Cortex XDR
- Familiarity with the MITRE ATT&CK framework, Active Directory, Azure / Entra ID, or Cloud security
- Experience in writing queries (SPL, KQL) and developing custom detection rules
חולץ מתיאור המשרה · מתעדכן אוטומטית
למי זה מתאים
התפקיד מתאים לאנשי אבטחת מידע עם לפחות שנת ניסיון במערכות SIEM ו-SOAR, ידע ברשתות ובלוגים, וזמינות מלאה לעבודה במשמרות 24/7. הוא פחות מתאים למי שאינו מעוניין לעבוד במשמרות סביב השעון.
תיאור המשרה המלא
המשרה המקורית · נשמר לעיון🚀 We're Hiring: Tier 1 SOC Analyst (24/7 Shifts)
🔍 Key Responsibilities
• Continuous real-time monitoring and analysis of security alerts across SIEM, SOAR, and EDR platforms.
• Perform initial triage, assess incident severity, and execute first-line incident response procedures (IR playbooks).
• In-depth log analysis across endpoints, servers, network appliances, and cloud environments.
• Document, escalate, and collaborate on complex security events with Tier 2/3, IR, and Threat Intelligence teams.
• Participate in post-incident reviews, refine runbooks, and help improve SOC detection capabilities.
🎯 Requirements
• At least 1 year of hands-on experience working with SIEM & SOAR systems.
• Strong familiarity with EDR, Firewalls, Proxy, and WAF solutions.
• Solid understanding of networking protocols (TCP/IP, DNS, HTTP/HTTPS).
• Good working knowledge of Windows and Linux operating systems.
• Proven ability to analyze security logs and investigate anomalies.
• Strong technical English proficiency (verbal and written).
• Full availability and willingness to work 24/7 rotating shifts.
⭐ Advantages
• Hands-on experience with: Splunk / Microsoft Sentinel / IBM QRadar.
• Experience with Cortex XSOAR (or equivalent SOAR platforms).
• Experience with CrowdStrike Falcon / SentinelOne / Cortex XDR.
• Familiarity with the MITRE ATT&CK framework, Active Directory, Azure / Entra ID, or Cloud security.
• Experience in writing queries (SPL, KQL) and developing custom detection rules.
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
- At least 1 year of hands-on experience working with SIEM & SOAR systems, Strong familiarity with EDR, Firewalls, Proxy, and WAF solutions, Solid understanding of networking protocols (TCP/IP, DNS, HTTP/HTTPS), Good working knowledge of Windows and Linux operating systems, Proven ability to analyze security logs and investigate anomalies