Medior SOC Analyst
JOIN OUR TEAM
At Levi Nine we are passionate about what we do. We love our work and together in a team we are smarter and stronger. We work in a dynamic and challenging environment with talented and forward-thinking people who are part of creative and innovative teams. We are looking for skilled team players who make change happen. Are you one of these players?
OUR PARTNER:
Our partner, ABN AMRO Clearing, is a global leader in the domain of clearing, offering access to a wide range of listed instruments on markets across the globe.
IT is at the heart of their organization with more than 30 different product teams and 10 different platform teams that are trying to build the best products & services for their customers.
Their presence in important financial centers like Amsterdam, Chicago, Sydney, Singapore, Tokyo Hong Kong, London, Sao Paulo, Frankfurt and Iasi, allows them to effectively serve clients worldwide and maintain close proximity to their diverse customer base.
THE ROLE INVOLVES:
The vacant role contains multiple aspects of work in a Security Operations Centre. The primary focus for this role would be Security Monitoring and Vulnerability Management.
For Security Monitoring it's about triaging security alerts and resolving incidents.
The alerts are often escalated via our partner's Managed Security Service Provider (MSSP), who provides Tier-1 SOC services to ABN AMRO Clearing, during the week and weekend. You will then swiftly perform triage and decide what actions should be done to contain the threat.
For the analysis you will have access to several sources such as XDR, Firewalls, endpoints, and application logging. If an alert escalates to a security incident, you either resolve it yourself or connect with a team member to resolve it together.
Within Vulnerability Management you analyze and escalate vulnerabilities. These vulnerabilities are then picked up by different teams within the organization. We utilize multiple types of scanners for this, both for internal and external scanning. It will be your job to support with coverage, align with stakeholders and escalate when remediation is required.
Besides the daily operations, a big part of your role will be identifying areas of improvement and working with stakeholders to get these done. An improvement can range from a small modification to the implementation of a new tool, all while working together and challenging the stakeholders who are a part of this process.
As an SOC Analyst you play a critical role in keeping the company safe by assessing the risk and impact of detected vulnerabilities and security incidents in a highly regulated environment.
Responsibilities:
Triage incoming cyber security alerts escalated from our partner's MSSP.
Investigate cyber security incidents and work with team members to contain and remediate them.
Analyze identified vulnerabilities and escalate them towards specific teams.
Identifying improvements in SOC tooling and capabilities such as EDR, SIEM or alert handling.
Supporting the implementation of new processes and tooling in the O&I team.
Analyze new security threats and validate our controls against them.
Guide stakeholders with their questions regarding Security Operations.
TECHNICAL PLAYGROUND:
4+ years' experience as an SOC Analyst and proven experience with the incident response life cycle: Vulnerability Management, Security Monitoring or Incident Response.
Understanding frameworks such as Cyber Kill Chain, MITRE ATT&CK.
Understanding of SIEM (Splunk) and/or EDR (Microsoft Defender) products.
Alert investigation: strong skills in performing deep analysis with specific tools and queries.
Experience handling medium incident responses.
Proven experience in analyzing & escalating vulnerabilities.
Threat hunting: ability to manage guided hunts and use Threat Intelligence in investigations.
NICE TO HAVE:
Ability to automate small tasks.
Certifications such as the following would be desirable but not mandatory: GCIH, GDAT, GCDA, GISP, OSDA, CCFR, SC-900, SC-200, Splunk.
A keen interest in cyber security and a desire to learn more.
Strong communication skills with stakeholders both technical and non-technical – joining vendor briefings.
A drive to improve the current way of working.
Relevant university degree in Computer Science, Engineering, or a related field.
SOFT SKILLS:
Fluent English, with good written and verbal communication skills.
Strong problem-solving skills and a proactive attitude.
Taking ownership on work that needs to be done, and you are flexible regarding possible standby hours.
Ability to give and receive feedback and not afraid to ask questions.
Flexible and adaptive working attitude - self-motivated and taking ownership.
Desire to continuously learn and improve in a complex, rapidly evolving environment.
- Locations
- Iasi
- Remote status
- Hybrid
- Technologies
- MITRE, Cybersecurity, SOC
- Seniority level
- Medior
Iasi
About Levi9 Romania
Levi9 is a nearshore technology service provider with around 1000 employees and 50+ customers. We specialize in custom made business IT – 95% of our work is on the revenue side of our customers. This is where time to market, high productivity, stable team velocity, and great quality through automation, agility, intensive interaction and understanding matter most.