Security Operation Center (SOC) Analyst

Vector Synergy
Den Haag, Netherlands
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Microsoft Windows Data Analysis Cyber Security System Configuration Identity and Access Management Issue Tracking Systems Intrusion Detection Systems Network Security Network Intrusion Detection Systems Performance Tuning ArcSight SIEM Tool Security Information and Event Management
+4 more
Snort (Software) Malware Firewalls (Computer Science) Splunk

Job description

  • Acting as the 1st line of response regarding a potential occurrence of a cyber-attack or security incident, supported by several automated tools such as IDS, log correlation engines and SIEM, ticketing system, and alerts and warning from internal and external sources;
  • Receiving, triaging, and responding to alerts, requests, and reports;
  • Analysing events and potential incidents;
  • Providing the primary support for Incident Responders;
  • Assessing whether a security incident or the level of exposure of a vulnerability is a true or false positive, tagging the vulnerability or incident with an initial severity classification, and activating the corresponding incident response playbook entry;
  • Following pre-defined procedures to perform technical tasks related to identity and access management (IAM).

Requirements

Do you have experience in Windows?, * Experience as a Security Operations Centre Analyst;

  • Minimum 1 year of experience in using, configuring, and tuning a security information and event management (SIEM) tool, ideally Splunk and/or ArcSight;
  • Experience with a log management solution such as HP ArcSight Logger and/or Splunk or equivalent;
  • Experience in writing and optimizing IDS signatures (preferably Snort and/or Suricata);

Knowledge on: Network security solutions and technologies such as:

  • Firewalls;
  • Network intrusion detection systems (IDS);
  • Intrusion prevention systems (IPS);
  • Host-based security solutions:
  • Host-based intrusion prevention systems (HIPS);
  • Malware end-point protection;
  • Operating system logs;

Good knowledge on:

  • MS Windows security events analysis;
  • Security analysis of firewall, proxy, and IDS logs;
  • Excellent analytical and critical thinking skills;
  • Very good interpersonal skills with the ability to work well both independently and in a team;
  • High degree of commitment and flexibility;
  • High level of customer and service orientation;
  • Ability to work effectively in an international and multi-cultural environment;
  • Readiness to work in a 24/7 shift mode;
  • Very good communication skills in English, verbally and in writing.

Desirable:

  • Experience in writing and optimizing YARA rules.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:23 min

Boosting security operations center productivity with intelligent data analysis

Chris Wysopal Chris Wysopal +2 · WWC 2024

1:48 min

Automating exploratory data analysis within training pipelines

Dora Petrella · WWC 2023

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

1:36 min

Performing exploratory data analysis to uncover underlying patterns

Julian Joseph · LIVE

Videos

See all

Related articles

See all