SOC L1 Analyst
- Role
- Security
- Experience
- Junior
The listing doesn't say where it hires from. Check the description or the employer's site before applying.
No BS summary
SOC L1 Analyst with 3+ years in security operations/incident response. Must be proficient with SIEM and EDR/IDS/IPS/firewalls and have cloud security experience in AWS or Azure; familiarity with MITRE ATT&CK and the Cyber Kill Chain is required.
Core skills
Required skills
Optional skills
About the Role
Our client is building a resilient defense against an evolving threat landscape, and we need a vigilant SOC Analyst to be the first line of defense. In this role, you will play a critical part in the security posture, actively monitoring our infrastructure, neutralizing threats in real-time, and helping refine the response playbooks. If you are passionate about cybersecurity and thrive in a fast-paced environment where your work directly safeguards sensitive fintech data, this is the opportunity for you.
What You Will Do
Proactive Monitoring: Maintain 24/7 visibility into our security landscape by monitoring alerts and events across SIEM, IDS/IPS, firewalls, and EDR platforms. Threat Detection & Triage: Perform initial triage on security events, investigating network traffic and system logs to identify potential malicious activity or anomalies. Incident Response: Lead the charge in managing security incidents, executing effective response actions, escalating critical issues, and coordinating across cross-functional teams to mitigate impact. Documentation & Reporting: Maintain granular records of all incidents and responses, creating comprehensive incident reports and updating our internal SOC documentation. Operational Improvement: Actively participate in post-incident reviews, translating lessons learned into concrete improvements for our SOC procedures and automated playbooks.
What You Bring
Experience: 3+ years of hands-on experience in security operations, incident response, or threat monitoring. Security Stack: Proficiency with industry-standard SIEM tools (e.g., Splunk, Microsoft Sentinel, QRadar, or ELK) and familiarity with EDR, IDS/IPS, and firewalls. Technical Knowledge: Solid understanding of cybersecurity principles, threat vectors, network protocols, and application-layer attacks. Cloud Proficiency: Practical experience with cloud security, specifically within AWS or Azure environments. Methodology: Familiarity with cybersecurity frameworks such as MITRE ATT&CK and the Cyber Kill Chain. Analytical Rigor: A track record of success in security investigation and proactive threat hunting. Communication: Exceptional attention to detail and the ability to clearly document technical findings for both technical and non-technical stakeholders. Bonus Qualifications: A Bachelor’s degree in Computer Science, Cybersecurity, or a related field, and familiarity with compliance frameworks (ISO27001, ISO27701, PCI DSS, GDPR).
What's in It for You
True Ownership: You will have the autonomy to influence our security roadmap and make architectural decisions that protect our production environments. Impactful Work: Your work directly safeguards real-money flows and critical financial data, making a tangible difference in the security of our users. Collaborative Culture: Join a cross-functional team of experts in engineering, fraud, and payments who value security and knowledge sharing. Continuous Growth: We invest in your professional development through support for advanced certifications, conference attendance, and research time. Competitive Benefits: We offer a comprehensive benefits package, including competitive compensation, health coverage, and flexible working arrangements.
What you'll do
- Proactive Monitoring: Maintain 24/7 visibility into our security landscape by monitoring alerts and events across SIEM, IDS/IPS, firewalls, and EDR platforms.
- Threat Detection & Triage: Perform initial triage on security events, investigating network traffic and system logs to identify potential malicious activity or anomalies.
- Incident Response: Lead the charge in managing security incidents, executing effective response actions, escalating critical issues, and coordinating across cross-functional teams to mitigate impact.
- Documentation & Reporting: Maintain granular records of all incidents and responses, creating comprehensive incident reports and updating our internal SOC documentation.
- Operational Improvement: Actively participate in post-incident reviews, translating lessons learned into concrete improvements for our SOC procedures and automated playbooks.
What they require
- 3+ years of hands-on experience in security operations, incident response, or threat monitoring.
- Proficiency with SIEM tools (e.g., Splunk, Microsoft Sentinel, QRadar, or ELK) and familiarity with EDR, IDS/IPS, and firewalls.
- Practical experience with cloud security, specifically within AWS or Azure environments.
- Familiarity with cybersecurity frameworks such as MITRE ATT&CK and the Cyber Kill Chain.
- Preferred: A Bachelor’s degree in Computer Science, Cybersecurity, or a related field, and familiarity with compliance frameworks (ISO27001, ISO27701, PCI DSS, GDPR).
Benefits
- Autonomy to influence our security roadmap and make architectural decisions that protect production environments.
- Support for advanced certifications, conference attendance, and research time.
- Health coverage.
- Flexible working arrangements.
- Collaborative cross-functional team with engineering, fraud, and payments.