Security operations team is responsible for ensuring that the Confidentiality,
Integrity, and Availability of the organization are consistently protected. The
individual working in the L1 SOC team operates and evaluates security monitoring
solutions, responding in a timely manner to security events identified. The role
involves applying analytical judgment to assess risks, investigate alerts, and
support incident response activities. This position requires working in a shift
schedule to provide 24/7 coverage within defined operational frameworks.
Job Functions and Responsibilities:
• Monitor, evaluate, and analyze cyber security events from various security
tools to identify potential threats and anomalies.
• Triage security events and incidents by applying structured analytical
methods, determine severity, and recommend or initiate appropriate remediation
actions in alignment with SOC procedures.
• Ensure accuracy, completeness, and quality of incident information to support
effective investigation and resolution.
• Analyze phishing emails reported by internal end users, assess potential
impact, and recommend mitigative actions.
• Escalate incidents to the L2 SOC team based on defined criteria, exercising
judgment within established governance frameworks.
• Follow up on remediation activities and validate closure to ensure risks are
effectively mitigated.
• Triage and manage general information security tickets, ensuring timely and
accurate resolution.
• Contribute to process optimization and operational efficiency by identifying
recurring issues, gaps, or opportunities for improvement in monitoring and
incident handling workflows.
• Drive solution-oriented outcomes impacting security posture and operational
effectiveness through proactive problem-solving and informed decision-making.
• Exercise discretion within defined governance frameworks and represent the
organization in stakeholder interactions with professionalism and sound
judgment.