SOC L0 Analyst
Company
IBM
Location
PL Wroclaw
Type
Full Time
Job Description
At IBM work is more than a job β itβs a calling: To build. To design. To code. To consult. To think along with clients and sell. To make markets. To invent. To collaborate. Not just to do something better but to attempt things youβve never thought possible. Are you ready to lead in this new era of technology and solve some of the worldβs most challenging problems? If so lets talk.
Your Role and Responsibilities
As a L0 Analyst you will deal with cyber security spam and phishing events as reported by SIEM TIP security tools email chat phone calls or direct messages with the final purpose to identify which event is a cyber security incident and to report GDPR-related events to the DPO.
In your daily work you will review alerts threat intelligence and security data identify threats that have entered the network and security gaps and vulnerability currently known. In this role you will identify events according to documented procedures and industry best practices. You will be required to follow the incident response plan and assist Cyber Threat Response Analysts when necessary.
You will be part of the SOC team that runs 24Γ7 on a rotating shift schedule.
β’ First point of contact for cyber security and GDPR-related events
β’ First point of analysis of threat intelligence reports
β’ Support investigation of cyber security and GDPR-related incidents
β’ Conduct events triage
β’ Conduct spam and phishing analysis and reaction and provide recommendations for future similar events
β’ Profile and trend events in the environment to determine if an incident needs to be created
β’ Provide incident communication and escalation as per the security incident response guidelines
β’ Create and deliver GDPR-related events reports and notices
β’ Hunt for suspicious anomalous activity based on data alerts or data outputs from various toolsets
β’ Escalate IT security tools issues when necessary
β’ Create and maintain daily activity log
β’ Perform administrative tasks as per management request (ad-hoc presentations trainings etc.)
β’ Assist continuous improvement of processes and work with other teams to improve alerts and rules in the incident monitoring systems
Required Technical and Professional Expertise
β’ At least one year experience in a similar role
β’ Experience with analyzing network and endpoint traffic
β’ Exposure to network devices Microsoft Windows systems UNIX systems and other security assessment tools (NMAP Nessus Metasploit Netcat etc.)
β’ Experience in threat intelligence report analysis
β’ Experience with log management and security information management tools
β’ Experience with SIEM SOAR UBA anti-malware spam phishing and TIP tools
β’ Knowledge of log formats from various log sources
β’ Knowledge of data protection regulation key principles
β’ English language at B2 level or above
Preferred Technical and Professional Expertise
β’ Experience with Splunk Enterprise Security solution (would be an advantage)
β’ Basic programming skills: Python C/C++/Perl and other scripting languages (would be an advantage)
β’ An understanding of contemporary and legacy security technologies (e.g. IDS Firewalls IAM SIEM)
Any of the following certificates will be a nice to have:
β’ Comptia Sec+ Comptia CySA+ CEH
β’ Security Essentials β SEC401 (optional GSEC certification)
β’ Intrusion Detection In Depth β SEC503 (optional GCIA certification)
β’ Hacker Guard: Security Baseline Training β SEC464
β’ Advanced Security Essentials β SEC501 (optional GCED certification)
β’ Hacker Techniques Exploits & Incident Handling β SEC504 (optional GCIH certification)
Date Posted
12/04/2024
Views
0
Similar Jobs
Analyst, Enterprise Risk Management - BD
Views in the last 30 days - 0
The Analyst Enterprise Risk Management ERM role at BD a leading global medical technology company involves supporting the ERM team in making riskinfor...
View DetailsSOC L0 Analyst - IBM
Views in the last 30 days - 0
IBM is seeking a Level 0 Analyst for their SOC team working 24x7 on a rotating shift schedule The role involves dealing with cyber security and GDPRre...
View DetailsServiceNow Business Analyst - EPAM Systems
Views in the last 30 days - 0
EPAM is hiring a dynamic ServiceNow Business Analyst with 4 years of experience in software development The role involves product requirements leading...
View DetailsProcurement Analyst - Value Engineering - BD
Views in the last 30 days - 0
BD a leading global medical technology company is seeking a Procurement Analyst The role involves using advanced PPCA methodologies to determine the s...
View DetailsSOC L0 Analyst - IBM
Views in the last 30 days - 0
The text is a job description for a L0 Analyst role in a SOC team responsible for handling cyber security GDPRrelated events and threat intelligence T...
View DetailsJunior AR Analyst (Order Management) with Italian - IBM
Views in the last 30 days - 0
IBM Consulting offers a career rooted in longterm relationships and collaboration with clients Youll work with visionaries to improve the hybrid cloud...
View Details