Security operations team is responsible for ensuring that the Confidentiality, Integrity, and Availability of the organization are consistently protected. The individual working in the L1 SOC team operates and evaluates security monitoring solutions, responding in a timely manner to security events identified. The role involves applying analytical judgment to assess risks, investigate alerts, and support incident response activities. This position requires working in a shift schedule to provide 24/7 coverage within defined operational frameworks.
Job Functions And Responsibilities
Monitor, evaluate, and analyze cyber security events from various security tools to identify potential threats and anomalies.
Triage security events and incidents by applying structured analytical methods, determine severity, and recommend or initiate appropriate remediation actions in alignment with SOC procedures.
Ensure accuracy, completeness, and quality of incident information to support effective investigation and resolution.
Analyze phishing emails reported by internal end users, assess potential impact, and recommend mitigative actions.
Escalate incidents to the L2 SOC team based on defined criteria, exercising judgment within established governance frameworks.
Follow up on remediation activities and validate closure to ensure risks are effectively mitigated.
Triage and manage general information security tickets, ensuring timely and accurate resolution.
Contribute to process optimization and operational efficiency by identifying recurring issues, gaps, or opportunities for improvement in monitoring and incident handling workflows.
Drive solution-oriented outcomes impacting security posture and operational effectiveness through proactive problem-solving and informed decision-making.
Exercise discretion within defined governance frameworks and represent the organization in stakeholder interactions with professionalism and sound judgment.