À propos de ce poste SOC Analyst - L3 Engineer chez HugoBank
About the Role
We are looking for a skilled SOC Analyst – L3 Engineer to join our Security Operations Center. The role will serve as the primary L3 technical escalation point and will support the management of a 24×7 SOC operation. The ideal candidate should have strong hands-on experience in SIEM, SOAR, Threat Intelligence, Threat Hunting, Incident Response, and MITRE ATT&CK.
Key Responsibilities
- Act as the L3 escalation point for complex security incidents and provide technical guidance to L1/L2 SOC Analysts.
- Support and coordinate 24×7 SOC operations, shift handovers, incident escalation, and SLA compliance.
- Manage, optimize, and troubleshoot commercial and open-source SIEM solutions.
- Develop and tune SIEM correlation rules, detection use cases, alerts, dashboards, and monitoring capabilities.
- Develop and maintain SOAR playbooks and automate security investigation and response processes.
- Utilize Threat Intelligence feeds, IOCs, TTPs, and threat actor information to enhance detection capabilities.
- Perform threat hunting and identify advanced threats and detection gaps.
- Implement and map security detections against MITRE ATT&CK and other relevant security frameworks.
- Lead/support incident investigation, containment, root-cause analysis, and remediation.
- Collaborate with IT, Network, Infrastructure, Application, and other teams for effective incident resolution.
- Support continuous improvement of SOC SOPs, playbooks, use cases, and security controls.
Requirements
- 3–4 years of hands-on experience in SOC/Cybersecurity/Security Operations.
- Strong experience with SIEM, including leading commercial and/or open-source solutions.
- Hands-on experience with SOAR and security automation.
- Practical experience with Threat Intelligence and Threat Hunting.
- Strong knowledge of MITRE ATT&CK Framework and security detection methodologies.
- Experience with Incident Response and Security Investigation.
- Good understanding of Windows/Linux, EDR/XDR, Firewalls, Network Security, Cloud, and Application logs.
- Scripting knowledge in Python, PowerShell, or Bash is an advantage.
- Experience in a 24×7 SOC environment is preferred.
Qualifications
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, IT, or related field.
- Relevant certifications such as CEH, Security+, CySA+, GCIH, GCIA, CISSP, or SIEM/SOAR/EDR vendor certifications are an advantage.