The job is responsible for monitoring, analysing, and responding to level 1 security alerts across on-premise and cloud infrastructures (AWS, Azure, GCP, OCI) 24/7 on shift.
It safeguards the organization by identifying risks, investigating incidents, and applying security policies, playbooks, and forensic techniques.
The role serves the business by protecting critical IT systems, data, and operations from threats, ensuring compliance, and enabling secure continuity of services.
By enhancing detection, automating controls, and producing actionable security metrics, it strengthens resilience and supports the organization’s trust, reputation, and long-term growth.
Job Responsibilities
Ensure that security alerts received on the SIEM, from the onprem data centre and the cloud Amazon Web Service (AWS), Microsoft Azure, Google Cloud Platform (GCP), Oracle Cloud Infrastructure (OCI) are properly investigated and resolved within the SLA.
Develop playbooks to guide analysis of security alerts.
Ensure the accurate completion and timely submission of shift handover reports and operational trackers.
Conduct basic monthly threat hunting.
Provide analysis of potential information security risks and recommend solutions.
Provide root cause analysis (RCA) for security alerts and incidents.
Assist Lead/Manager in the development of processes and automations to improve SOC’s effectiveness and efficiency.
Ensure timely follow ups for incident ticket containment mitigation and remediation actions.
Ensure all assigned training and certifications are completed within the stipulated timeframes.
Ensure the timely completion of all tasks assigned at the department, section, and unit levels.
Prompt escalation of critical issues to the Team Lead and Management to ensure rapid resolution.
Job Requirements
Degree in IT or a related disciplines such as: Computer Science (Strongest foundation for automation/scripting) or Cybersecurity or Information Assurance or Digital Forensics or Network Engineering.
Minimum of 2 years of IT Security–related working experience in a Security Operations Center (SOC) environment.
Good Working knowledge of Microsoft Office (Word, Excel, etc.).
Good written and verbal communication skills.
Understanding on the application of threat intelligence for threat detection, including IOCs, TTPs vulnerabilities etc.
Ability to work with a team and a good team player.
Highly self-motivated and directed.
Knowledge of common security tools and technology such as SIEM, IPS, AV, XDR, Wireshark.
Operating system fundamentals, such as processes, services, scheduled tasks.
Cloud Proficiency: Hands-on experience with AWS (GuardDuty, Security Hub), Azure (Microsoft Defender for Cloud), or GCP (Security Command Center).
At least 1 year of hands-on applied experience with the technical skills listed below:
KQL, SPL and SIEM/Data Lake platforms (e.g. Splunk, Sentinel).