Soc Analyst l2
Job Details
Job Title:
Security Operation Analyst – SOC Analyst Tier 2
Section:
Information Security
Functional Level:
Entry
Department:
Information Security
Sector
Information Security
Reporting Lines
Reports directly to:
Information Security Section Head
Job Purpose
Handle the daily operations of the Information Security function.
Job Responsibilities
Investigate escalated security incidents and determine impact
Perform deep endpoint investigations
Conduct threat hunting activities across endpoints and network logs
Analyze attacker behavior, persistence, and lateral movement
Develop and improve detection use cases and correlation rules
Tune SIEM and EDR alerts to reduce false positives
Support containment, eradication, and recovery activities
Collaborate with IT and infrastructure teams during incidents
Produce incident reports and root cause analysis
Generate monthly and quarterly reports
.
KPIs (Key Performance Indicators)
Number of systems with known vulnerabilities. 35%
Number of days to deactivate former employee credentials. 30%
Frequency review of the third-party accesses. 25%
Reporting 10%
Competency Model
Technical competency level
1. Web Development Languages (e.g. ASP.net, Java, JavaScript, etc.) (B)
2. Web frameworks (e.g. jQuery, Bootstrap, Django). (B)
3. Database administration (B)
4. Open Source Security Testing Methodology Manual (OSSTM) (B)
5. Open Web Application Security Project (OWASP) (B)
6. Technical writing (B)
Specifications: Qualifications, Experience, skills
None/R&W High School Diploma Bachelor Masters
Specialization:
Minimum of a bachelor's degree or equivalent in information technology, computer science or related field.
Good experience in threat management, incident response and threat hunting.
Excellent Scripting skills (bash, python, Perl, PowerShell).
Strong understating and Hands-on experience in Digital Forensics and Incident Response.
Hands-on experience in IT security systems such as: "SIEM, EDR, Threat Intelligence Platforms, Security Scanners and Vulnerability Management , Identity Management, FIM, "
Direct experience in Security Operations Center work with Network Event, Threat and/or Intel Analysis.
Knowledge of various security methodologies and processes, technical security solutions (firewall and intrusion detection systems) and Internet protocols and applications.
Ability to analyze endpoint, network, and application logs.
Requires knowledge of forensics, network analysis, log analysis, systems hardening, encryption technologies, certificates, mobile, and web application security.
Requires theoretical knowledge of information systems security standards and practices (e.g., access control and system hardening, system audit and log file monitoring, security policies, and incident handling).
Additional skills: database, web components, automation components, repository components.
SANS, (ISC)² , eLearn Security and Ec-council certifications is a plus.
Minimum 2 years of relevant experience.
Conditions of Employment