SOC Analyst

IBM • BUDAPEST, HU

Company

IBM

Location

BUDAPEST, HU

Type

Full Time

Job Description

Introduction
  • SIEM & Incident Management (Splunk)
    • Independently analyse SIEM alerts in Splunk correlate across multiple data sources and enrich with threat intelligence feeds.

    • Conduct root-cause analysis and propose improvements to detection logic.

    • Collaborate with engineering teams to enhance Splunk detection rules and SOPs.

    Validate escalations and ensure incident creation in ticketing platform e.g. Service Now is accurate.

  • Analyse complex e-mail or hotline cases that fall outside SOPs.

  • Escalate major incidents to CDC.

NextGen Endpoint Protection (CrowdStrike) incidents
  • Perform in-depth triage and investigation of CrowdStrike Falcon incidents.

  • Correlate alerts with endpoint telemetry Splunk logs and threat intelligence.

  • Take pre-approved remediation actions via automated workflows.

  • Conduct root-cause analysis on recurring incidents.

  • Recommend whitelist/blacklist updates to reduce false positives.

Email Malware Prevention
  • Analyse suspicious emails including attachment and URL behavioural analysis.

  • Initiate mitigation measures (IoC blocking proxy actions sandbox validation).

  • Classify severity and escalate critical events to CDC.

  • Produce intelligence reports on emerging email-borne threats.

Mentorship & Coordination

  • Support continuous improvement of workflows and operational procedures

Your role and responsibilities

The SOC Analyst is responsible for deep-dive investigation advanced analysis and resolution of security incidents escalated from automated systems. L1 analysts provide contextual threat analysis enrichment and remediation while working closely with CDC and engineering teams. They ensure incidents are accurately classified mitigated and documented.

Required education
Bachelor's Degree
Preferred education
Master's Degree
Required technical and professional expertise
  • Solid understanding of cyber kill chain MITRE ATT&CK and incident response.
  • Proficiency with SIEM (Splunk) EDR (CrowdStrike) and SOAR automation workflows.
  • Hands-on experience with e-mail security sandboxing and phishing analysis.
  • Knowledge of malware behavior threat intelligence sources and IOC enrichment.
  • Strong analytical and investigative skills with the ability to handle complex cases.
Preferred technical and professional experience
  • Bachelor’s degree in Computer Engineering IT Cybersecurity or related field.
  • Security certifications (e.g. Splunk Certified Cybersecurity Defense Analyst CySA+GIAC GCIH or similar).

1–4 years of SOC analyst or incident response experience.

Apply Now

Date Posted

12/04/2025

Views

0

Back to Job Listings ❤️Add To Job List Company Info View Company Reviews
Positive
Subjectivity Score: 0.9

Similar Jobs

Back-end Developer - IBM

Views in the last 30 days - 0

The text describes a developer role involving feature development code reviews collaboration with crossfunctional teams maintaining services documenta...

View Details

HR Advisor with German - IBM

Views in the last 30 days - 0

This text describes a HR Advisor role at IBM Consulting emphasizing collaboration client relationships and career growth opportunities It outlines res...

View Details

HR Advisor with Spanish - IBM

Views in the last 30 days - 0

This text describes a career opportunity at IBM Consulting emphasizing longterm client relationships collaboration and innovation It outlines the role...

View Details

Project manager, Technology Expert Labs - IBM

Views in the last 30 days - 0

The text describes IBMs Technology Expert Labs emphasizing their role in helping clients adopt and optimize IBM technology solutions globally It highl...

View Details

Expert Labs Project Administrator - IBM

Views in the last 30 days - 0

The role involves supporting financial objectives through project management and accounting skills requiring proficiency in English and Italian with a...

View Details

Cloud Serverless Front-End Developer - IBM

Views in the last 30 days - 0

IBM Cloud Code Engine is a new platform for developers to create serverless applications on Kubernetes clusters The role involves designing developing...

View Details