What are the responsibilities and job description for the SOC Analyst OR Security Operations Center Analyst position at DCM Infotech Limited?
Job Details
Title: 3rd Shift Cyber Security Operations Analyst
Location: Lowell, AR, (Intially Remote)
Duration: 12 Months
The 3rd Shift Cyber Security Operations Analyst monitors and protects the organization's systems, networks, and data during overnight hours. This role involves real-time threat detection, incident response, and maintaining the overall security posture of the organization. The analyst works as part of a Security Operations Center (SOC) team and plays a critical role in identifying and mitigating security risks during non-business hours.
Key Responsibilities:
Threat Monitoring and Detection:
1. Continuously monitor security tools, such as SIEM systems, intrusion detection/prevention systems (IDPS), firewalls, and endpoint protection platforms, to detect potential security threats or anomalies.
2. Analyze and investigate security alerts, identifying true threats versus false positives.
3. Conduct proactive threat hunting to identify vulnerabilities or malicious activities.
4. Monitor and analyze network traffic, system logs, and user activity to ensure compliance with security policies.
Incident Response and Management:
1. Respond to security incidents, including malware infections, phishing attempts, unauthorized access, and other potential breaches.
2. Execute containment, eradication, and recovery procedures to minimize the impact of incidents.
3. Collaborate with senior analysts or SOC managers to escalate complex or high-risk incidents.
4. Document all incidents in detailed reports, including root cause analysis and lessons learned.
System Maintenance and Updates:
1. Perform regular updates and maintenance on security tools and platforms to ensure they function effectively.
2. Assist in applying patches and updates to address known vulnerabilities.
3. Support the integration of new security technologies or tools into the existing infrastructure.
Collaboration and Communication:
1. Communicate effectively with team members and stakeholders to provide updates on incidents and overnight activities.
2. Participate in shift handovers to ensure continuity of security operations across shifts.
3. Assist in the development of documentation, playbooks, and standard operating procedures (SOPs) for SOC operations.
Compliance and Reporting:
1. Ensure security operations align with organizational policies, regulatory requirements, and industry standards (e.g., ISO 27001, NIST, GDPR).
2. Prepare and submit daily reports summarizing overnight security events and activities.
3. Contribute to security audits and compliance reviews.
Continuous Improvement:
1. Stay updated on emerging cyber threats, vulnerabilities, and industry best practices.
2. Provide recommendations to improve detection, response, and prevention capabilities.
3. Participate in training, simulations, and drills to enhance incident response readiness.
Qualifications:
Education:
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field.
Equivalent work experience may be considered.
Experience:
1-3 years of experience in cybersecurity, SOC operations, or a related IT field.
Familiarity with SIEM tools, IDPS, firewalls, and endpoint detection platforms.
Experience working in a 24/7 operational environment is a plus.
Skills and Competencies:
Knowledge of cybersecurity principles, threat landscapes, and attack vectors.
Strong analytical and problem-solving skills for investigating security events.
Proficiency in using security tools and platforms (e.g., Splunk, QRadar, Sentinel).
Understanding of networking concepts (TCP/IP, DNS, VPNs) and operating systems (Windows, Linux).
Ability to work independently during overnight hours and make quick, informed decisions.
Certifications (preferred):
CompTIA Security , CySA , or equivalent certifications.
GIAC Certified Incident Handler (GCIH).
Certified Ethical Hacker (CEH).
Splunk Core Certified User or similar tool-specific certifications