L1 SOC Analyst at Cyber Dome
Cyber Dome
Published 1 month ago · Expires 3 weeks from now
Job description
Role Summary
The L1 SOC Analyst provides first-line monitoring, triage, and incident escalation within the Security Operations Centre. This role focuses on continuous surveillance of security events, identifying suspicious activities, conducting basic investigation, and ensuring timely escalation to L2/L3 teams following approved playbooks and SLAs. The L1 Analyst is critical in maintaining 24/7 detection coverage and supporting the organization's cybersecurity posture.
Key Responsibilities
Security Monitoring & Alert Handling
- Monitor SIEM dashboards, alerts, and log sources in real-time (Securonix, Splunk, Rapid7 InsightIDR, QRadar)
- Perform initial triage of alerts based on severity and defined SOPs
- Validate false positives versus true positives using available tools
- Escalate incidents to L2/L3 and SOC Lead when thresholds are met
Incident Response Support
- Conduct first-level investigation of suspicious activity (e.g., brute force, malware detection, privilege misuse)
- Gather evidence and document findings in JIRA
- Execute basic containment actions when permitted (e.g., isolate host, block IOC, disable account) following playbooks
Log Management & Reporting
- Review and analyze logs from endpoints, servers, cloud platforms, and applications
- Ensure all log sources are properly ingested and reporting successfully within the SIEM
- Generate daily SOC shift reports and handover documentation
Threat Intelligence Consumption
- Review threat intelligence feeds and correlate IOCs with observed alerts
- Report emerging or unusual patterns to L2/L3 teams for further analysis
Compliance & Operational Duties
- Adhere strictly to SOC SOPs, runbooks, and escalation matrices
- Maintain accurate documentation, incident timelines, and evidence
- Participate in rotating shifts (day/night/weekend)
Required Skills & Competencies
Technical Skills
Foundational knowledge required. Please note: The original job description appears incomplete in this section. Please provide complete technical skill requirements to finalize this listing.