The SOC Analyst will be responsible for continuous monitoring, detection, analysis, and initial response to security events using SIEM platforms and CrowdStrike Falcon EDR. The role focuses on alert triage, endpoint security analysis, incident escalation, and supporting threat detection and response operations while adhering to defined SOC processes and SLAs.
For CrowdStrike Falcon EDR Operations administrator: -
a. Monitor CrowdStrike Falcon console for endpoint detections and behavioural alerts. b. Analyse:
i. Process execution trees ii. Command-line arguments,
iii. File hashes.
iv. Network connections.
Perform response actions based on SOP:
I. Endpoint containment/isolation ii. File quarantine. iii. IOC blocking.
Assist in post-incident remediation and recovery
Technical Skills Required: -
SIEM a)
Hands-on experience with at least one SIEM platform: b) Splunk / QRadar / ArcSight/any other c) Robust understanding of:
i. Log sources and event normalisation ii. Alert tuning and rule logic iii. Correlation and use-case analysis