···
Log in / Register

SOC Monitoring Analyst - Level 1

Indeed
Full-time
Onsite
No experience limit
No degree limit
Praça do Patriarca, 62 - Historic Center of São Paulo, São Paulo - SP, 01002-010, Brazil
Favourites
Share
Some content was automatically translatedView Original

Description

Job Summary: A professional responsible for monitoring security events, performing initial alert triage, and supporting incident investigations, ensuring rapid and effective responses. Key Highlights: 1. Monitor security events and perform initial alert triage. 2. Support incident investigations and execution of response playbooks. 3. Collaborate on continuous improvement of SOC processes and controls. SOC Monitoring Analyst \- Level 1 Job Description: This professional will be responsible for **monitoring security events, performing initial alert triage, and supporting incident investigations**, ensuring rapid and effective responses in accordance with defined operational standards. Responsibilities: * Monitor dashboards, alerts, and events in SIEM tools (Wazuh, Grafana, etc.). * Perform **initial triage** of alerts and categorize them based on severity and threat type. * **Escalate** relevant alerts to the Level 2 team or coordination team per operational procedures. * Document incidents, evidence, and actions taken in the ticketing system (TheHive, GLPI, etc.). * Support the execution of **response playbooks** in collaboration with Level 2 analysts and the incident response team. * Participate in use-case reviews and detection rule adjustments under technical supervision. * Collaborate on continuous improvement of SOC processes and controls. Requirements: * Basic knowledge of networking (TCP/IP, DNS, HTTP, VPN, etc.). * Familiarity with operating system logs, firewalls, antivirus, and EDR solutions. * Interest in learning about SIEM, SOAR, and frameworks such as MITRE ATT&CK. * Understanding of vulnerabilities and common attacks (phishing, brute force, malware, etc.). * Strong written communication skills for incident documentation and operational reporting. **Preferred Qualifications:** * Entry-level cybersecurity certifications such as Security\+, Blue Team Level 1 (BTL1\), Jr Penetration Tester (eJPT), or Wazuh Fundamentals. * Basic knowledge of Python, Bash, or PowerShell for simple automation. * Technical English for reading reports and documentation. * Intermediate Spanish will be a plus for communication with international clients.

Source:  indeed View original post
João Silva
Indeed · HR

Company

Indeed
Cookie
Cookie Settings
Our Apps
Download
Download on the
APP Store
Download
Get it on
Google Play
© 2025 Servanan International Pte. Ltd.