The Chance
As the SOC Analyst Tier 2 you will be responsible for monitoring, detecting, containing, and remediating security incidents utilizing a suite of security software tools. This critical role supports the internal JLR SOC and directing an outsourced tier 1 2 SOC MSSP to deliver robust security operations.
Key Performance Indicators
- Number of identified vulnerabilities
- Number of vulnerabilities contained
- Number of vulnerabilities mitigated
- Time to detect
- Time to respond
- Time to mitigate
Key Responsibilities:
- Manage a suite of Security Products.
- Evaluates incidents identified by tier 1 analysts
- Uses threat intelligence such as updated rules and Indicators of Compromise (IOCs) to pinpoint affected systems and the extent of the attack.
- Consolidating data from alert triage to provide context necessary to initiate Tier-3 work
- Conduct security research and intelligence gathering on emerging threats
- Can offer SME advice to security driven projects.
- Ability to provide technical and service leadership to T1 analysts
- Good understanding of ITIL processes,
including Change Management, Incident Management and Problem Management.
- Contribute to Incident Response investigations working with the Incident Response team.
- Continual development of analysis playbooks and tradecraft
- Proactively contribute to SOC strategy by refining standards, processes and procedures.
- Handle incidents across Windows, Mac, and Linux platforms.
- Develop and improve processes for incident detection and the execution of countermeasures.
- Actively maintains awareness of developments in the intrusion analysis, incident response and information security fields.
- Maintaining SecOps documentation.
- Conduct proactive threat research
Key Interactions
- External Security Operations Centre (currently TCS)
- Manufacturing
- Engineering
- Data Protection Officer / Legal
- Business Protection
- Other IT functions
- GDPR