SOC Tier 1 Analyst - Junior
Role details
Job location
Tech stack
Job description
The SOC Tier 1 Analyst (Junior) acts as the first line of defense within the Security Operations Center. The role focuses on the analysis and resolution of risk objects and security alerts generated by detection rules maintained within the SOC environment.
On a daily basis, the SOC Tier 1 Analyst is responsible for reviewing assigned alerts and determining whether the observed activity is malicious or legitimate. This assessment is performed through guided analysis using multiple security tools and dashboards available in the SOC environment.
The SOC Tier 1 Analyst also contributes to the continuous improvement of detection capabilities by identifying alerting rules that generate non-relevant or excessive alerts and formally documenting improvement recommendations to enhance detection quality and reduce false positives.
The role includes on-call or shift-based duties, during which the analyst is responsible for handling high-risk objects that generate a large volume of alerts or carry elevated risk scores. Shifts are organized on a rotating basis (morning or afternoon).
During periods of lower operational workload, the Tier 1 Analyst may also be involved in occasional supporting or transversal SOC tasks, although the primary focus remains alert analysis and risk object resolution., * Analyze and resolve security alerts and risk objects
- Determine whether detected activities are malicious or benign
- Prioritize and handle high-risk objects during assigned shifts
- Document analysis results and decisions
- Identify detection gaps or excessive alerting and propose improvements
- Escalate incidents when required, following SOC procedures
- Adhere to SOC processes, playbooks, and operational guidelines
Requirements
Do you have experience in Cybersecurity?, * Junior / entry-level SOC position
- Strong analytical mindset and attention to details
- Basic understanding of cybersecurity concepts and alert-based analysis
- Comfortable working in a shift-based SOC environment
- Fluent in English - French and/or Dutch is an asset