Security Operations Center (SOC) Tier 1 Analyst

Javen Technologies, Inc
Farmington Hills, MI, United States
12 days ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours
Job source

Tech stack

Cloud Computing Security CompTIA Network+ CompTIA Security+ Cyber Security Information Systems Digital Data Issue Tracking Systems Intrusion Detection and Prevention Knowledge Management Phishing Security Information and Event Management Transmission Control Protocol (TCP)
+5 more
Data Logging ServiceNow IT Service Management Malware Information Technology 3-tier Architectures

Job description

  • Summary/Basic Purpose: Provide a detailed overview of the position including its purpose and desired results. Describe leadership responsibility if a management position. Use paragraph form.
  • The Security Operations Center is responsible for providing 24/7, 365 monitoring, detection, and response capabilities for Comerica. This includes event, cloud security, and DLP monitoring, as well as a role in the incident response process. The Tier 1 SOC analyst primarily serves as the initial triage and investigation point for the SOC and would escalate incidents on an as needed basis.
  • The Tier 1 Security Operation Center (SOC) Analyst is responsible for proactively monitoring and performing initial triage / investigation of security incidents and alerts to identify any malicious activity. Besides the initial triage and investigation, Tier 1 Analysts are expected to escalate security incidents according to defined escalation policies to Tier 2, Tier 3, and SOC leadership for further investigation / response.

Essential Duties/Responsibilities: List the essential duties and responsibilities of the job. Each duty/responsibility should represent at least 10% of the job, totaling 100%, not to exceed 7 items., SOC Analysis

  • Monitor security incidents for, endpoints, network, and cloud domains, being generated by the SIEM tool and ticketing system.
  • Initial triage and investigation of incidents assigned through the ticketing system, following established playbooks for specific incident types.
  • Respond, mitigate, and eradicate security threats, with guidance from Tier 2, Tier 3 analysts, as well as SOC leadership.

Documentation and Support

  • Provide consistent and quality documentation of actions taken to triage / investigate incidents.
  • Assist senior staff in development of documentation / knowledge management articles for the SOC.
  • Handle sensitive information in accordance with the Corporate Information Protection Policy.
  • Collaborate with other Engineering and Operations teams to troubleshoot, respond, and improve detection capabilities.
  • Other duties as assigned

Physical Demands and Working Conditions: This section is pre-populated in the online system. Please provide information that may differ from a typical office job to your Compensation partner.

  • Identify and distinguish colors and shapes in either physical and/or digital format
  • Maintain a stationary position
  • Operate office machinery including but not limited to computers, printers, scanners, phones, etc.
  • Move through work location to access files, machinery, or other items to complete a job/task
  • Move and/or position 0-20 pounds
  • Move and/or position over 20 pounds
  • Position self to work environment based on task assigned such as filing in high or low cabinets
  • Ability to count and handle currency and coinage
  • Travel required

Requirements

  • High School/GED
  • Description: With 2 years relevant and/or transferable experience OR - Preferred
  • 4 Yr/bachelor s degree: Degree in Computer Science, Engineering, Information Systems, or Cyber Security or equivalent degree

Minimum Experience

Specific Experience:

  • Transferable and/or relevant work experience
  • Experience using various operating systems and industry standard monitoring, logging, alerting and investigation processes.

Licenses/Certifications:

  • Foundational Cybersecurity / IT certifications (e.g. CompTIA Network+, CompTIA Security+, GCIA, GCIH, GREM, or GPEN) preferred

Job Specific Knowledge/Skills:

  • Solid understanding of Cybersecurity concepts and frameworks.
  • Proven, excellent analytical skills.
  • Working knowledge in the use of tools such as SIEM / IT Ticketing technologies, EDR, Email Gateway s, Malware Analysis Sandbox.
  • Understanding of networking (TCP/IP networks and protocols) concepts.
  • Understanding of phishing and malware techniques
  • Strong written and oral communication, documentation, and organizational skills.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:00 min

The exponential growth of digital data and cloud storage

Murphy John

1:23 min

Understanding the complexity of cybersecurity domains

Jennifer Reif · LIVE

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

Videos

See all

Related articles

See all