Overview
IT Security Analyst role at RHB Banking Group. This SOC L2 position is an integral part of 24 / 7 SOC monitoring. The SOC L2 analyst acts as shift subject-matter expert (SME) and leads on incident detection and analysis techniques.
Responsibilities
- Collaboration and Escalation : respond to security alerts using a combination of technology solutions and documented processes on a 24 x 7 x 365 basis; act as a point of escalation for Level-1 analysts in a 12-hour shift rotation; escalate suspected incidents to L3 with detailed analysis and actionable recommendations; interface and collaborate with other teams for incident escalations and resolution; work closely with SOC Head to improve security operations and address identified deficiencies.
- In-Depth Analysis : perform due diligence and in-depth analysis on escalated security alerts from Level-1 analysts and escalate to the respective team for timely action; assist in threat hunting activities to identify potential vulnerabilities.
- Incident Response : participate in incident response steps, perform root cause analysis and recommend solutions to mitigate risks.
- Coaching and Mentoring : support Level-1 alert analysis by providing advanced analysis to include recommending containment and remediation processes; mentor Level-1 analysts to improve detection capability and provide feedback on work quality.
- Continuous Improvement : challenge and suggest improvements to existing processes and procedures in a fast-moving information security environment; receive and review tuning requests from Level-1 and provide recommendations on use case tuning and optimization of security systems.
- Documentation & Reporting : ensure all relevant processes are documented, complete, accurate and updated as needed.
Other Skills Required (if Applicable)
Demonstrated ability to work in a team environment, train and coach other team members.Experience with investigating using detective technologies such as SIEM, packet capture analysis, host forensics and memory analysis tools.Understanding and knowledge of threat landscape in terms of tools, tactics, and techniques of attacks.Excellent analytical and problem-solving skills.Great communication skills, both written and verbal; ability to communicate technical and non-technical issues effectively.Hands-on experience in working with a Security Operations Centre.Relevant technical and industry certifications are a plus, e.g. SANS certifications.
Seniority level
Entry levelEmployment type
Full-timeJob function
Information TechnologyNote : This description reflects the responsibilities and requirements of the role; other information like locations and postings are provided for context on job listings.
#J-18808-Ljbffr