Mid-Level SOC Analyst
Adept Consulting Services, Inc. · Harrisburg, PA · 5 days ago
On-siteOTHRFull-time
Description of Duties
- Perform ongoing, on-site information security and network monitoring with proactive response for mission-critical communication sites and systems.
- Capture, log, and respond to events received from email, chat, telecommunication systems, and other security systems, ensuring accurate documentation of incoming data.
- Perform security investigation for alerts escalated within the Security Operation Center, determining full scope, potential root cause, and potential impact.
- Follow, create, and improve established playbooks and SOPs used by the SOC.
- Document security incidents, responses, and related information in accordance with established procedures
- Analyze advanced logs, network capture, end-point telemetry to identify malicious activity and indicators of compromise (IOCs).
- Conduct initial threat hunting to proactively identify security anomalies and adversary activity.
- Conduct tuning and optimization of existing detection rules, alerts, and correlation logic to reduce false positives and improve detection fidelity.
- Participate in root cause analysis or lessons learned sessions.
- Maintain flexibility to work in various shift rotations to support 24/7/365 operations, including days, nights, holidays, and weekends.
- Provide incident response support as needed and directed during network and security events providing support for incident resolution.
Decision Making
- Make informed and timely decisions on the appropriate response to security alerts.
Essential Functions
- Use personal computer/laptop with Microsoft Office products and other business software.
- Analyze and interpret various information.
- Create queries, reports and scripts leveraging current security coding and SIEM query languages.
- Prioritize tasks effectively.
- Communicate effectively orally and in writing.
- Work independently and as a team member.
Requirements
- Mid-level experience in SOC operations and security alert investigation.
- Experience with SIEM tools, security queries, reports, and basic scripting.
- Ability to analyze logs, network traffic, and endpoint data to identify threats and IOCs.
- Experience with threat hunting, incident response, and root-cause analysis.
- Experience tuning detection rules and reducing false positives.
- Experience following and improving SOC playbooks and procedures.
- Strong documentation, troubleshooting, communication, and prioritization skills.
- Ability to work independently and as part of a team.
- Willingness to work onsite in rotating 24/7/365 shifts, including nights, weekends, and holidays.
Benefits
- Health Care Plan (Medical, Dental & Vision)
- Retailment Plan (401k)
- PTO