Position Overview
We are seeking a highly motivated SOC Operator to join our global security operations team. This role is critical in monitoring, detecting, analyzing, and responding to security incidents across the enterprise. The ideal candidate will have hands-on experience in incident response, security investigations, and threat detection, with exposure to Red, Blue, and Purple Teaming exercises. This position requires strong technical skills, analytical thinking, and the ability to collaborate with cross-functional teams to contain and remediate threats effectively.
Key Responsibilities
Security Monitoring & Analysis
- Monitor SIEM dashboards, EDR s, and security telemetry for suspicious activity across endpoints, networks, and cloud environments.
- Perform initial triage, classification, and escalation of security s based on severity and impact.
- Correlate events from multiple sources to identify potential attack patterns and lateral movement.
Incident Response & End-User Support
- Provide first-line and second-line support for security incidents, including phishing, malware infections, and account compromises.
- Guide end-users through containment and remediation steps for security-related issues.
- Document incident details, actions taken, and lessons learned in the incident management system.
Security Investigation & Threat Hunting
- Conduct in-depth investigations of security incidents, including log analysis, forensic review, and root cause determination.
- Participate in threat hunting activities to proactively identify indicators of compromise (IOCs) and advanced threats.
- Collaborate with threat intelligence teams to enrich investigations with contextual data.
Red/Blue/Purple Teaming Support
- Assist in Blue Team defensive operations by validating detection rules and improving fidelity.
- Support Purple Team exercises by working with Red Team to simulate attacks and validate detection/response capabilities.
- Provide feedback to improve SOC playbooks and detection engineering.
Incident Management & Reporting
- Follow incident response playbooks and escalate incidents to senior analysts or IR teams as needed.
- Generate daily, weekly, and monthly SOC reports on incident trends, response metrics, and threat landscape.
- Ensure compliance with industry standards (ISO 27001, NIST CSF) and internal security policies.