Description
Job Summary:
We are seeking a Senior SOC Analyst to monitor, detect, respond to incidents, and conduct security testing—protecting organizational assets and advancing the organization's security posture.
Key Highlights:
1. Monitor, detect, and respond to security incidents
2. Conduct security testing (Penetration Testing) on applications, infrastructure, and networks
3. Contribute to the continuous improvement of the organization's security posture
Job Description
We are looking for a Senior SOC Analyst to perform monitoring, detection, incident response, and security testing activities—actively contributing to the protection of organizational assets and the continuous advancement of the organization's security posture. Experience with 24x7 / night-shift SOC operations is required.
Main Responsibilities
Monitor security events and alerts using tools such as SIEM, EDR, and IDS/IPS
Investigate security incidents through log analysis, event correlation, and evidence analysis
Execute incident response, including containment, eradication, and recovery activities
**Conduct security testing (Penetration Testing), including:**
Controlled identification and exploitation of vulnerabilities
Testing of applications, infrastructure, and networks (within defined scope)
Support in impact analysis and mitigation of identified vulnerabilities
Create, tune, and improve detection rules, alerts, and response playbooks
Perform threat intelligence analysis and track emerging attack vectors
Escalate critical incidents and high-impact vulnerabilities to senior teams or specialized units
Produce technical and executive reports for both incidents and security testing
Support continuous improvement initiatives for SOC processes, controls, and maturity
**Requirements:**
Technical Requirements
Previous experience in Information Security or SOC (2–4 years)
**Proficiency with SIEM tools (e.g.:** Splunk, IBM QRadar, Microsoft Sentinel)
**Familiarity with EDR/XDR solutions (e.g.:** CrowdStrike, Microsoft Defender, SentinelOne)
Solid knowledge of networking and protocols (TCP/IP, DNS, HTTP/HTTPS, SMTP)
Knowledge of Windows and Linux operating systems
Experience in log analysis, incident investigation, and response
Familiarity with offensive and defensive frameworks such as MITRE ATT\&CK
Basic scripting or automation skills (Python, PowerShell, or Bash)
Fundamental understanding of penetration testing and vulnerability assessment, including interpretation of results
Preferred Qualifications
Hands-on penetration testing experience (Web, Infrastructure, or Network)
Knowledge of OWASP Top 10
Certifications such as CEH, Security\+, CySA\+, SC\-200, DCPT
Experience in SOC-as-a-Service (MSSP) environments