We are looking for an experienced Security Analyst with a minimum of 2 years of hands-on experience and mandatory CrowdStrike certification to join our Security Operations Center (SOC) team. In this role, you will be a key part of our 24x7x365 white-glove SOC, responsible for monitoring, advanced alert triage, threat hunting, and incident mitigation across our next-generation security platform.
You will leverage the CrowdStrike Falcon ecosystem alongside integrated email and network telemetry to defend our clients' environments against sophisticated cyber threats.
Key Responsibilities-Security Monitoring & Platform Management
- Monitor and analyze security alerts and logs utilizing the
CrowdStrike Managed Next-Gen SIEM Complete
platform.
- Oversee endpoint, cloud, and identity alerts using
CrowdStrike Falcon Complete
,
Falcon Cloud & Identity
, and
Exposure Management + ONUM
.
- Monitor integrated telemetry streams, including
Abnormal Email Security
and
Palo Alto Network Ingestion
.
- Follow and optimize defined SOC runbooks and escalation procedures.
Advanced Alert Triage & Investigation
- Perform deep-dive triage of complex security alerts to identify true positives and zero-day threats.
- Review raw logs, behavioral indicators, and threat intelligence to isolate malicious activity from false positives.
- Conduct proactive threat hunting within the Falcon platform to identify hidden vectors of compromise.
- Collect forensic details and escalate critical, validated incidents to senior incident response teams.
Incident Response & Containment Actions
- Execute rapid response actions directly through the Falcon console, including network containment/endpoint isolation.
- Mitigate identity risks by blocking malicious IPs/domains and performing account password resets or session revocations according to SOPs.
- Collaborate closely with engineering and senior analysts during active, high-severity incidents.
Log Analysis & Threat Modeling
- Query and filter massive d