SOC Analyst Tier 2
Join an organizational Security Operations Center in Jerusalem to investigate and respond to cybersecurity incidents. This is a full-time, on-site shift role with on-call duties and 24/7 availability as needed.
Responsabilidades
- Monitor, identify, analyze, and respond to cybersecurity incidents.
- Independently investigate security alerts and incidents, correlate information from multiple sources, and identify suspicious or anomalous activity.
- Investigate incidents across endpoint, identity, network, and cloud environments using SIEM/SOAR, EDR/XDR, threat intelligence, and security investigation tools.
- Conduct proactive threat hunting based on indicators of compromise, tactics, techniques and procedures, and threat intelligence.
- Triage incidents and assess their scope, impact, and severity.
- Perform mitigation and containment according to procedures and playbooks, escalating complex incidents to Tier 3 and incident response teams.
- Document investigations and actions, write incident reports, and identify ways to improve future detection and response.
- Work with networks, communications, operating systems, and network and endpoint security products.
- Work shifts on site, participate in on-call rotations, and provide 24/7 availability as needed.
Requisitos
- At least 3 years of experience in cybersecurity or information security.
- Experience in a Tier 2 SOC Analyst or equivalent role, including independent incident investigation, advanced alert analysis, threat hunting, and initial response actions.
- Strong knowledge of networks, communications, operating systems, and security processes.
- Familiarity with security products and their implementation, configuration, operation, maintenance, and management.
- Experience with SIEM/SOAR and EDR/XDR tools.
- Knowledge of account and permission management, access control, system monitoring, and information security incident handling.
- High level of English.
- Relevant education.