Senior Soc Analyst

Senior Soc Analyst
Empresa:

Tn Portugal



Função de trabalho:

Tecnologia da informação

Detalhes da Vaga

.Senior SOC AnalystPortoPorto, Porto, PortugalJob Description:The main activities are the ones below:Detection, categorization and investigation of infrastructure, applications and security incidents.Vulnerability management on critical vulnerabilities (handling, categorization).Leading incident response plans.Follow-up of remediation plans.Implementation of detection scenarios and treatment of associated alerts.The L2 SOC Analyst is responsible for monitoring and analyzing the organization's networks and systems on a daily basis to detect, identify, investigate, and mitigate potential threats. They must be able to identify anomalous behavior, recognize patterns of malicious activity, and take appropriate corrective action.In addition to their daily duties, the L2 SOC Analyst will provide recommendations for improving security posture and assist with incident response plans, policies, and procedures. Some additional responsibilities may include recommending tools or solutions, participating in audit activities, providing reporting on security events/incidents, and collaborating with other teams across the organization.Main Tasks and Responsibilities:The candidate will have 3 main missions:Analysis:Participation in improving correlation and log analysis rules.Conduct investigations and research including statistics.Interpret or perform first level (Sandbox or manual) minimum scans on malicious codes.Improve our Threat Intelligence activity.Handling incidents:Creating and managing service requests via our ticketing tools (Service Snow / Sec Ops / The Hive).Qualify and analyze these elements to determine the cause of the incident, the mode of operation of the attack (vulnerabilities use, tactics, techniques), the scope, and the perimeter of compromise.Training:Knowledge transferring in-house and writing documentation.Apart from these activities, the candidate will have to maintain and develop their expertise in techniques and tools of digital investigation and methods and tools for analysis (monitoring, training, international conferences, etc.).Main Requirements:The candidate must be operational on the security tools used in the BPCE IS and master the architectures in place. Solid knowledge in most of the following technical areas is required, keeping in mind that no one is an expert in every topic. The ideal candidate should have advanced problem-solving skills and a background in cybersecurity engineering.SIEM/SOAR:Knowledge of the operating principles of Information Monitoring and Security Event Solutions (SIEM).Good experience of Splunk and Regex search syntax.Good experience with The Hive.SYSTEM/NETWORK:Good knowledge of network and system architectures.Knowledge of the operation of intrusion detection probes and event log correlation tools.SECURITY:Good knowledge of the Mitre Attack framework and countermeasures linked to the techniques and tactics.Good knowledge of Information monitoring and analysis tools and methods


Fonte: Jobtome_Ppc

Função de trabalho:

Requisitos

Senior Soc Analyst
Empresa:

Tn Portugal



Função de trabalho:

Tecnologia da informação

Fullstack Developer

```html About Us Founded in 1995, we are an international tech consulting company certified by Great Place to Work and in second place in The Best Workplaces...


Desde Noesis Portugal - Porto

Publicado a month ago

It Service Desk Technician | Técnico Suporte (M/F)

Descrição da empresaA MysticInvest é uma holding de cruzeiros fluviais e de expedição cuja empresa mãe é a Pluris Investments. Considerada um dos maiores ope...


Desde Mystic Invest - Porto

Publicado a month ago

Bi Support Analyst (M/F/D)

A NIW é uma empresa de Consultoria que atua em diversas áreas, com destaque para as Tecnologias de Informação. Fazemos parte da Salvador Caetano e a nossa mi...


Desde Salvador Caetano - Porto

Publicado a month ago

Programador Web / Web Designer

Essa vaga expirou no Indeed. Possíveis motivos: a empresa não está aceitando inscrições, não está contratando ou está analisando inscrições.PROGRAMADOR WEB /...


Desde Vigion - Inovação & Segurança - Porto

Publicado a month ago

Built at: 2024-09-20T13:23:38.388Z