Description
Job Summary:
Work on the frontline of the SOC, focusing on continuous monitoring, initial triage of security events, and supporting incident response under supervision.
Key Highlights:
1. Continuous monitoring of security alerts and events
2. Support in incident validation and classification
3. Ongoing development in threat intelligence and security fundamentals
Work Mode: On-site
**12x36 Shift (Night Shift)**
? Job Mission
Work on the frontline of the SOC, focusing on continuous monitoring and initial triage of security events, supporting incident validation and response under supervision. The professional contributes to early threat detection, alert classification based on severity, and execution of basic containment actions—reducing risks and supporting the team in rapid incident response. May also handle more complex cases and perform related tasks as required by the department.
? Key Responsibilities
* Continuously monitor security alerts and events using tools such as **SIEM, EDR, NDR, XDR, and related solutions**
* Perform initial alert triage based on context and defined playbooks
* Support incident validation and classification according to severity and type
* Execute basic containment actions under supervision, including:
+ Endpoint isolation via EDR
+ Blocking malicious IPs, domains, or URLs
+ Temporary deactivation of suspicious accounts
+ Supporting automations via SOAR
* Document evidence, analysis, and actions clearly and systematically in ITSM/SOAR systems
* Escalate incidents requiring in-depth investigation
* Contribute to continuous improvement of monitoring and response processes
* Continuously develop knowledge of threats, attack techniques, and security fundamentals
? Technical Requirements
**Mandatory**
* Basic knowledge of Information Security
* Understanding of networks, operating systems, and protocols
* Familiarity with SOC concepts and incident response
* Analytical ability and attention to detail
**Desirable**
* Prior experience in SOC, NOC, or monitoring environments
* Knowledge of SIEM, EDR, or related tools
* Familiarity with security frameworks (MITRE ATT&CK, NIST, ISO 27001\)
* Technical English for reading