Tier I SOC Analyst

Remote - Ontario, Canada

CyberClan

Headquartered in Vancouver, Canada CyberClan has dedicated teams throughout Canada, the United States, the United Kingdom and Australia to provide first-class Incident Response & Breach Response services, Cyber Extortion, Ransomware,...

View all jobs at CyberClan

Apply now Apply later

Overall Purpose


The Security Operations team exists to protect the client by proactively detecting and responding to cyber security threats.


Our SOC Analysts are our front line of cyber defence: monitoring and assessing cases, correlating observables, mitigating and defending against malicious cyber activity and adapting to an ever-changing threat landscape.


Operating as a triage specialist responsible for the monitoring management and configuration of relevant security tools, containing and remediate attacks, as well as preventing intrusion and unauthorized access to critical data and devices.     


This role requires willingness to work shifts (including unsociable hours and bank holidays where these fall into your shift pattern) as part of a 24x7 team.


Principal Duties and Responsibilities


  • Monitor and identify cyber security threats that pose a risk, or have the potential to pose a risk, to the client.
  • Monitoring SIEM alerts effectively to minimize downtime and restore services.
  • Triage alerts and alarms across a broad range of security controls as they come into the SOC and assess urgency to escalate to Tier 2 as appropriate.
  • Ensure investigation steps are clearly documented and accurately escalated to Tier 2 when needed.
  • Provide Tier 1 case resolution for basic security cases including generating initial reporting, providing follow-ups and requesting information and resolution activity.
  • Responsible for providing communication directly with CyberClans’ customers regarding security incidents and other related topics.
  • Responsible for understanding where threats may appear.
  • Responsible for producing and maintaining documentation relevant to both the SOC and position.
  • Responsible for updating and offering continual improvement to the knowledge base.
  • Work with the CyberClan global team when responding to security incidents.
  • Support the SOC team research global security events, issues and trends to produce security advisories for customers based on findings.
  • Responsible for managing and configuring security monitoring tools.
  • Investigating intrusion attempts and performing in-depth exploit analysis.
  • Conducting cyber threat research and analysis for purposes of improving the strength of network security.


  • Assist with defining, testing and operating new ways of working with new technology solutions or processes supplied to the SOC team. 
  • Provide analytical feedback on client network traffic patterns.
  • Provide analytical feedback related to malware and other network threats. 
  • Accept, manage and update service requests and incidents to ensure contracted Service Level Agreements are met.



Generic Duties and Responsibilities


  • To continuously develop both technical and personal skills required within the role and assist with development of other staff.
  • Participate in identification and delivery of Service Improvement Plans.
  • Proactively support business KPIs.
  • Understand and comply with all Information Security policies. 
  • Understand and comply with all company policies.
  • Interact with strategic incident response and threat intelligence vendors.
  • To undertake other responsibilities, training and tasks as reasonably requested by line management.
  • Undertake periodic assurance reviews and produce associated reporting as required.
  • Participate in CyberClan internal security awareness initiatives and other training requests 
  • The job description may be altered at any time in line with the level of the post to meet changing requirements, but only in full consultation with the post holder.


Personal Specifications:

Qualifications:

  • Educated to GCSE level or equivalent
  • Cyber Security Qualification (COMPTIA or equivalent experience)
  • ITIL Foundation


Skills, Knowledge and Experience:

  • Knowledge and experience of SOC tooling to identify threats.
  • Experience of collaboration tools
  • Keen analytical mind and approach
  • Previous experience of SOC analysis beneficial
  • Proactively shares own expertise with others
  • Knowledge and experience of IT systems, networking and security threat landscape including:
    • Network fundamentals for example OSI stack, TCP/IP, DNS. HTTPS, firewall logs
    • Cloud technologies (AWS, Google Cloud, Azure)
    • Active Directory, Group Policies, PowerShell
    • Endpoint protection applications (Antivirus, Web Filtering, ATP, Encryption)
    • IDP/IPS Systems
    • SIEM tools
    • SOAR is an added advantage
  • Knowledge of malware capabilities, attack vectors and impact.


Personal Qualities:

  • Excellent interpersonal skills sufficient to develop professional relationships and rapport amongst key stakeholders
  • Strong team player
  • Genuine enthusiasm and drive to work within cyber security.
  • Excellent customer service skills
  • Good written skills to write explanations of systems, regulations and or procedures.
  • Good verbal communication
  • Ability to identify and suggest continual improvement
  • Good analytical and problem-solving skills
  • Ability to adapt to organisational change
  • Proven ability to manage varied workload
  • Ability to work unsupervised and under pressure.
Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  56  25  0

Tags: Active Directory Antivirus AWS Azure Cloud CompTIA DNS Encryption Exploit Firewalls GCP Incident response IPS ITIL KPIs Malware Monitoring Network security PowerShell SIEM SOAR SOC TCP/IP Threat intelligence Threat Research

Perks/benefits: Team events

Regions: Remote/Anywhere North America
Country: Canada

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.