remote
Security Operations Center SOC Analyst - EAB
Systems Engineer
Join a dynamic SOC team to monitor, detect, and respond to security incidents using SIEM platforms, threat‑hunting techniques, and automation scripts, ensuring the protection of critical educational data and infrastructure.
About the role
Key Responsibilities
- Monitor security alerts and events across the organization using SIEM tools such as Splunk and identify potential threats in real time.
- Investigate and triage security incidents, conduct root‑cause analysis, and coordinate remediation efforts with IT and engineering teams.
- Develop and execute threat‑hunting queries and playbooks to proactively uncover hidden adversary activity.
- Perform log collection, parsing, and analysis from diverse sources (firewalls, endpoints, cloud services) to support investigations.
- Automate repetitive tasks and enrich detection capabilities using Python scripts and APIs.
- Maintain and improve SOC processes, documentation, and reporting to meet compliance and audit requirements.
Requirements
- 2+ years of experience in a Security Operations Center or similar environment.
- Hands‑on experience with SIEM platforms (e.g., Splunk, QRadar) and log‑analysis tools.
- Strong knowledge of incident response methodologies, threat‑hunting techniques, and common attack vectors.
- Proficiency in scripting languages, preferably Python, for automation and data manipulation.
- Excellent analytical, communication, and problem‑solving skills, with the ability to work under pressure.