Techowl Infosec
Techowl Infosec is looking for an experienced Cyber Security Analyst to join our Security Operations Center (SOC). The ideal candidate will lead the investigation and response to critical cybersecurity incidents, improve detection capabilities, mentor junior SOC analysts, and strengthen the organization's overall security posture. This role is ideal for professionals with strong expertise in incident response, SIEM platforms, threat hunting, digital forensics, and security automation. Key Responsibilities Incident Response Investigate and respond to high and critical severity security incidents. Perform endpoint, network, cloud, and identity forensic investigations. Execute containment, eradication, and recovery activities. Lead incident response bridge calls during major security incidents. Prepare root cause analysis (RCA) and post-incident reports. Detection Engineering Develop, optimize, and maintain SIEM detection rules. Tune alerts to reduce false positives while improving threat detection. Build use cases aligned with the MITRE ATT&CK framework. Identify detection gaps and recommend security improvements. Threat Hunting & Monitoring Monitor security events using SIEM and EDR platforms. Conduct proactive threat hunting activities. Analyze Indicators of Compromise (IOCs) and attacker Tactics, Techniques & Procedures (TTPs). Mentorship & Documentation Review investigations completed by L1 and L2 analysts. Mentor junior SOC team members. Update incident response playbooks and documentation. Maintain high-quality incident records and technical documentation. Reporting Present executive-level incident summaries. Generate weekly and monthly SOC performance reports. Recommend process improvements based on security findings. Reporting Present executive-level incident summaries. Generate weekly and monthly SOC performance reports. Recommend process improvements based on security findings. Required Skills Security Incident Response Security Operations Center (SOC) SIEM Administration Threat Hunting Malware Analysis Digital Forensics Network Security Endpoint Detection & Response (EDR) Cloud Security Monitoring MITRE ATT&CK Framework NIST Incident Response Framework Cyber Kill Chain Python PowerShell Windows Security Linux Administration Network Packet Analysis DNS & Proxy Log Analysis Technical Skills SIEM Platforms Splunk Microsoft Sentinel IBM QRadar EDR Solutions CrowdStrike Falcon SentinelOne Microsoft Defender for Endpoint Cloud Platforms AWS CloudTrail Azure Monitor Google Cloud Security Command Center (GCP SCC) Digital Forensics Volatility FTK Autopsy Scripting Python PowerShell Preferred Certifications GIAC Certified Incident Handler (GCIH) GIAC Certified Enterprise Defender (GCED) GIAC Security Essentials (GSEC) Microsoft SC-200 Splunk Certified Power User Splunk Certified Architect CISSP (Preferred) Eligibility Criteria Minimum 5 years of cybersecurity experience. At least 3 years of Security Operations Center (SOC) experience. Experience handling critical security incidents independently. Hands-on experience in SIEM rule creation and optimization. Experience mentoring junior SOC analysts. Strong analytical and troubleshooting skills. Excellent written and verbal communication skills. Benefits Competitive Salary Career Growth Opportunities Learning & Certification Support Work on Enterprise Security Projects Collaborative Security Team Exposure to Advanced Threat Detection Technologies
We do not charge any fees for jobs. Do not pay anyone for job offers. Report any such requests immediately.
Posted On
1 day ago
Department
IT & Information Security - Other
Work Place
office
Industry
IT Services & Consulting