Sobre esta vaga de Senior SOC Analyst | MDR na Uvcyber
What You'll Do:
-
Works as part of a Cyber Defense team that works 24/7 on rotational shifts.
-
Continuously monitor and respond to advanced threats and evolving attack vectors across multiple environments
-
Perform in-depth investigation and triage of security alerts to determine root cause, impact, and relevance.
-
Correlate alerts and telemetry from SIEM and log sources like EDR, IPS, Firewall and threat intelligence platforms to identify real threats.
-
Handle detections targeting cloud infra/services/applications.
-
Provide recommendations for containment, mitigation, and recovery to client or internal response teams.
-
Contribute to the development and fine-tuning of detection rules, analytics, and use cases to enhance threat visibility and strength overall defense posture.
-
Collaborate closely with Threat Intelligence, SOAR, and Engineering teams for enrichment and contextual analysis.
-
Document investigations, findings, and recommendations in accordance with SOC SOPs and reporting standards.
-
Serve as a subject matter expert on detection and response methodologies, including SIEM, SOAR, threat intelligence, log analysis, network and EDR telemetry, and other response techniques.
-
Develop and maintain accurate documentation which includes SOPs, playbooks, runbooks and SOC operational procedures.
-
Mentor and guide junior analysts, foster a culture of continuous learning and operational excellence and ensure adherence to operational quality benchmarks and SLAs.
What You've Done:
-
4+ years of experience in incident response, SOC Tier 2 or equivalent.
-
Strong understanding of adversary tradecraft (MITRE ATT&CK, Cyber Kill Chain, etc.).
-
Deep understanding of cloud security concepts.
-
Experience with EDRs, SIEMs, SOARs and log pipelines.
-
Solid grasp of Windows, Linux, and cloud security.
-
Familiarity with scripting languages for analysis.
-
In-depth understanding of network protocols, endpoint artifacts, memory, and log analysis.
-
Excellent problem-solving and analytical thinking.
-
Ability to work under pressure during incidents and with minimal supervision.
-
Strong documentation and communication skills, especially when dealing with stakeholders.
-
Collaborative, yet capable of deep focus and individual contribution.