Overview
SOC Analyst — Bluecube Technology Solutions - An Ekco Company
We are seeking a highly skilled and motivated Security Operations Center (SOC) Level 2 Analyst with advanced proficiency in Microsoft Sentinel. The successful candidate will play a pivotal role in enhancing our organization's cybersecurity posture, focusing on incident analysis, investigation, and response using Microsoft Sentinel.
Responsibilities
- Incident Analysis : Utilize Microsoft Sentinel to conduct in-depth analysis of security incidents and alerts; investigate and assess the scope, impact, and root cause of incidents, providing detailed reports.
- Incident Response : Actively participate in incident response activities, coordinating with Level 1 and Level 3 analysts; develop and execute comprehensive incident response plans, ensuring efficient containment and eradication.
- Threat Hunting : Proactively hunt for potential security threats and vulnerabilities using Microsoft Sentinel; stay informed about emerging threats and provide recommendations for enhancing detection capabilities.
- Security Operations : Serve as a subject matter expert on Microsoft Sentinel, providing guidance to Level 1 analysts; collaborate with other security teams to implement and enhance security controls; develop and maintain detailed documentation, including playbooks and standard operating procedures.
- Continuous Improvements : Identify opportunities for process improvement within the SOC, contributing to the enhancement of workflows and tools; stay current with industry trends, new threats, and advancements in cybersecurity.
Qualifications
Bachelor’s degree in Cybersecurity, Information Technology, or a related field (or equivalent work experience).Minimum of 3 years of experience in a SOC Level 2 environment, with a focus on incident analysis and response.Advanced expertise in working with Microsoft Sentinel for security monitoring and incident investigation.Strong understanding of cybersecurity principles, threat intelligence, and incident response best practices.Relevant certifications such as CompTIA Security+, CySA+, Microsoft SC-200, GIAC C|IH, or equivalent would be an advantage.Proficient in scripting and automation for SOC tasks (e.g., PowerShell).Strong analytical and problem-solving skills with meticulous attention to detail.Bonus points if you have familiarity with cloud security concepts and platforms (especially Microsoft Azure), experience with other SIEM solutions, knowledge of network protocols, firewall technologies, and intrusion detection / prevention systems, and familiarity with regulatory requirements and frameworks (e.g., GDPR, NIST, ISO 27001).Why Ekco
Microsoft’s 2023 Rising Star Security Partner of the yearVMware & Veeam top partner statusRanked as 4th fastest growing technology company in the Deloitte Fast50 AwardsEkco is committed to diversity, equality, inclusion and belongingInternal mobility and opportunities for development and progressionFlexible working with a family-friendly focusLocation
Kuala Lumpur - Malaysia
Employment type
Full-timeJob function
Information TechnologyIndustries
IT Services and IT Consulting#J-18808-Ljbffr