Senior SOC Analyst
ST Engineering Group
Job Summary:
The Tier 3 Senior SOC Analyst acts as the Deputy SOC Manager and provides leadership for SOC operations. The role includes threat hunting, incident analysis, process optimization, unveil presentation, and team mentorship, ensuring the highest level of security operations for MSSP clients.
Responsibilities:
Leadership and Oversight:
- Serve as the Deputy SOC Manager and lead Tier 1 and Tier 2 analysts by example.
- Conduct training sessions, provide coaching, and ensure continuous skill development for the team.
- Plan relevant certifications for Tier 1 and Tier 2 analysts, ensuring proper progression with certifications arranged yearly.
Threat Hunting and Incident Analysis:
- Actively hunt for threats, identify unknown vulnerabilities, and close security gaps within networks.
- Identify all security attack vectors, classify incidents, and assess their impact.
- Review all escalations from Tier 1 and Tier 2 analysts, ensuring comprehensive analysis and daily updates to the SOC Manager
- Proactively update documentation, processes, workflows, and other operational aspects for continuous improvement.
- Threat Detection:
Develop and maintain threat detection use cases based on:
- MITRE ATT&CK techniques
- Threat intelligence reports
- Security incident trends
- Business-specific risks
- Create and optimize SIEM detection rules
- Validate detection effectiveness through testing and simulation exercises
- False Positive Management:
- Work closely with Tier 2 analysts to gather feedback and evidence on false positives.
- Finetune use cases to reduce false positives across all customers.
- Ensure consistent application of false positive reduction measures for all MSSP clients
Operational Excellence:
- Maintain oversight of SOC processes to ensure compliance and operational effectiveness.
- Plan and implement improvements to SOC operations, focusing on proactive threat detection and response.
- Monitor and "police" SOC workflows, providing tracking and daily updates to SOC leadership.
Technology Refresh:
- Contribute to the testing of new technology (such as AI)
- Review and compare against current technology to improve SOC operations
Requirements:
- Extensive experience in SOC operations, including threat hunting and advanced incident analysis.
- Strong understanding of SIEMs, threat intelligence platforms, and security tools.
- Leadership experience with a track record of mentoring and developing security teams.
- Relevant certifications (e.g., CISSP, CISM, GCIH) are highly preferred.
- Excellent communication, documentation, and organizational skills.
- Ability to handle high-pressure situations and critical security incidents effectively.
- A collaborative mindset to work effectively with other SOC tiers and managers.
- Strong analytical and problem-solving skills to address complex security challenges.
- Commitment to continuous learning to stay updated with the latest security trends and technologies.
- Adherence to SOC playbooks, standard operating procedures, and compliance requirements.
- Willingness to work in a dynamic 24/7 SOC environment.
Location: Ang Mo Kio.
Similar jobs
More Security jobs →Caretaker
University of the Built Environment
Job Description Employment status and working hours Fixed term for 12 months, part time for 22 hours per week. In this role your weekly working pattern will be Monday to Thursday inclusive from…
Incident Response Engineer, UK Security Operations, Hampshire
Minimum qualifications: Bachelor's degree or equivalent practical experience Completed relevant industry course/certification offerings such as CEH, GIAC or CompTIA Sec+. 5 years of experience in…
Lead Application Security Engineer
Brunswick Group
Opportunity The Lead Application Security Engineer will join Brunswick's Information Security team and play a key role in shaping how the firm embeds security into application design, development,…