SUMMARY
DACTA is looking for a highly motivated and experienced
Senior SOC Analyst
to join our Security Operations Centre (SOC) team. The Senior SOC Analyst will be responsible for monitoring, investigating, analysing, and responding to complex security incidents across various security platforms and technologies, while also managing and leading a small team of SOC Analysts.
RESPONSIBILITIES
Continuously monitor and analyse security events and alerts from various sources, including SIEM, EDR/XDR, firewalls, IDS/IPS, endpoint security, network security, and other security infrastructure.
Investigate and respond to security incidents, including complex and high-severity cybersecurity events.
Conduct detailed analysis of security events, logs, network traffic, endpoint activities, and other relevant security data to determine the severity, impact, scope, and root cause of incidents.
Perform advanced incident investigation and determine appropriate containment, eradication, recovery, and remediation actions.
Conduct threat hunting activities to proactively identify suspicious activities, indicators of compromise (IOCs), attacker behaviours, and potential security threats.
Develop and utilize threat-hunting queries and techniques to identify emerging threats and malicious activities.
Analyse and correlate information from multiple security sources to identify attack patterns, anomalies, and potential security incidents.
Perform analysis of malware, suspicious files, URLs, domains, IP addresses, and other indicators of compromise where required.
Analyse threat intelligence and security research to identify emerging cybersecurity threats, vulnerabilities, attack techniques, and indicators that may affect the organisation or its customers.
Apply recognised cybersecurity frameworks and methodologies, including MITRE ATT&CK, during security investigations and threat analysis.
Develop, maintain, and improve SIEM correlation rules, detection rules, dashboards, alerts, and security monitoring use cases.
Assist in tuning and optimizing security tools and detection mechanisms to improve detection accuracy, reduce false positives, and enhance overall SOC capabilities.
Identify gaps in existing security monitoring and recommend improvements to security tools, processes, procedures, and detection capabilities.
Coordinate with IT, network, infrastructure, application, and other technical teams to facilitate timely investigation, containment, and remediation of security incidents.
Participate in the management and response of major or critical security incidents and provide technical recommendations to relevant stakeholders.
Conduct root cause analysis and post-incident reviews and provide recommendations to prevent recurrence of security incidents.
Prepare and maintain detailed incident reports, investigation findings, root cause analysis, remediation recommendations, and other security documentation.
Develop and maintain incident response procedures, playbooks, investigation guides, and SOC operational documentation.
Provide technical guidance and knowledge sharing to SOC team members to improve investigation and incident-handling capabilities.
Participate in regular SOC meetings, cybersecurity training, tabletop exercises, knowledge-sharing sessions, and continuous improvement initiatives.
Maintain up-to-date knowledge of cybersecurity threats, vulnerabilities, attack techniques, security technologies, and industry best practices.
Perform other cybersecurity and SOC-related duties and responsibilities as assigned by management.
Manage and lead a small team of SOC Analysts to ensure effective day-to-day SOC operations and timely handling of security incidents.
REQUIREMENTS
Bachelor's degree in Cybersecurity, Information
Technology, Computer Science, Information Security, or a related field, or equivalent professional experience.
5 years or more of relevant experience in SOC operations, cybersecurity, security monitoring, incident response, or a related cybersecurity environment.
Strong hands-on experience in security monitoring, incident investigation, and incident response, SIEM platforms, such as Splunk, ArcSight, QRadar, Microsoft Sentinel, or similar technologies.
DACTA was established with the aim of simplifying the perception of complexity surrounding digital security challenges and solutions. Drawing on over two decades of cybersecurity expertise, DACTA's founders and senior team of cybersecurity specialists recognized the need for a fresh, innovative, and transformative approach in how security vendors implement digital security for their clients. Their vision was to create a simpler and more effective methodology. Although we acknowledge that cybersecurity is by no means an easy task, we firmly believe that the burden of implementing and managing digital security should not fall on our clients. Small and medium-sized enterprises (SMEs) already have numerous responsibilities to handle on a daily basis: developing their products, delivering services, satisfying customers, and growing their businesses. We are committed to ensuring that digital security does not hinder these activities. It is our sole responsibility, operating round the clock, 365 days a year, to address this concern. We understand that our clients should not be burdened with solving and managing digital security; it is our duty to take care of it. At DACTA, our primary mission is to provide our clients with peace of mind. To accomplish this, our team of cybersecurity professionals and experts tirelessly work towards developing, tailoring, and managing digital services and cybersecurity solutions.