ICC - Security Operations Analyst - Cyber Defense
Core
Monitor, investigate, and respond to cyber threats in a global 24/7 Security Operations Centre across cloud, endpoint, and network environments.
Role type
Senior Security Operations Analyst (Cyber Defense)
Builds
Security monitoring capabilities, incident response outcomes, and detection quality improvements
Domain
Cybersecurity / SOC Operations
Required skills
SIEM analysis, EDR management, log analysis, incident triage, threat investigation, cloud security, Microsoft security technologies, Linux/Windows administration
Preferred skills
Tier 1/2 incident response, AWS security monitoring, scripting (Python/PowerShell/Bash), security certifications
Technologies
Microsoft Sentinel, Splunk, QRadar, ArcSight, ELK, Microsoft Defender for Endpoint, CrowdStrike, Azure, AWS, GCP
Responsibilities
Monitor and triage security alerts across SIEM and EDR platforms; Analyze logs from Windows, Linux, databases, and network devices; Investigate suspicious activity and assess incident severity; Support incident response, remediation, and containment; Collaborate with incident response specialists for escalation; Optimize detection rules and reduce false positives; Prepare technical reports and maintain SOC documentation
Seniority
Senior, hands-on IC