Description
Job Summary:
We are seeking a SOC Analyst 1 to work in Detection Engineering & Automation, conducting research, developing, and evaluating detections, with a focus on SOAR automations.
Key Highlights:
1. Focus on research, development, and evaluation of security detections.
2. Development of SOAR automations for SIEM alert response.
3. Work with security frameworks (CKC, MITRE ATT&CK).
We seek a professional to work in **Detection Engineering & Automation** as a **SOC ANALYST 1**, responsible for researching, developing, testing, and evaluating detection performance. The ideal candidate must understand SOC concepts, Information Security frameworks, and/or have participated in incident response processes. This position focuses on developing SOAR automations to automatically respond to alerts generated by the SIEM.
### **Responsibilities and Duties:**
* Conduct research based on analysis of cyber threat reports;
* Create and maintain detection use cases;
* Analyze events/logs to identify anomalous behaviors;
* Develop detection rules based on research and analysis of SIEM (Security Information and Event Management) technologies;
* Create automations via playbooks for automated responses using SOAR (Security Orchestration, Automation, and Response).
### **Requirements and Qualifications:**
* Education: Currently pursuing a degree in Information Security, Computer Science, Technology, or related fields.
**Soft Skills**
* Proactivity: identifying improvements and proposing solutions;
* Self-directed learning: eagerness to continuously learn new things;
* Engagement and commitment to work quality;
* Discipline and effective time management;
* Teamwork;
* Strong communication skills.
**Hard Skills**
* Knowledge of Windows and Linux operating systems;
* Knowledge of cloud environments (AWS, GCP, Azure, etc.);
* Knowledge of processes related to cyber threat monitoring;
* Familiarity with CKC (Cyber Kill Chain) and MITRE ATT&CK frameworks;
* Familiarity with major SIEM (Security Information and Event Management) platforms;
**Preferred Qualifications**
* Experience developing automation scripts — Python;
* Knowledge of YAML language;
* Familiarity with SIGMA format.