Engineer - SOC Analyst
Doha, QA
Job Title
Engineer - SOC Analyst
Job Scope
The SOC Analyst is accountable for detecting security incidents in the SOC and translating security impacts to the wider business. S/He monitors the security control, reviews the incident tickets and leverages emerging threat intelligence to identify affected systems and scope of attack.
Main Duties and Responsibilities
- Participate in the gathering, analysis and communication of threat intelligence through the intelligence process/lifecycle;
- Apply technical skills to analyze files and related components using tools and technologies;
- Perform in-depth analysis of incidents created from L1 team;
- Understand the underlying behavior and implication on a computer and network environment;
- Respond to customer queries and concerns within a given timeline to address related concerns;
- Determine and direct remediation and recovery efforts;
- Understand vulnerability scans and review vulnerability assessment reports;
- Manage, configure and improve security monitoring tools (SIEM) among others as per client needs;
- Promote a professional image of the company and the professional services function at all times.
Position Requirements
- At least one security certificate (CEH, OSCP, CISSP, CCNP Sec, etc.);
- Any CCNP – Cisco Certified Network Professional or equivalent;
- Any non-vendor security certificate (CISSP, CISM, ISO27001, GCIA, GCIH, GCFA, GCFE, etc.);
- Understanding of log formats (LEEF, CIF…) and protocols (syslog, ftp, logfie…);
- Knowledge of security devices such as IDS/IPS, HIDS/HIPS, anomaly detection, Firewall and Antivirus systems and their log output;
- Network forensics: network traffic protocols, traffic analysis (i.e. Network flows and PCAP);
- Working knowledge of SIEM tools (such as RSA, ArcSight, Splunk and QRadar and etc.)
Education
Bachelor’s degree in Computer Science or any other related field
Experience
At least 2 years of relevant experience
#LI-AA4