Cyber Security Associate
Job Description
SOC Monitoring
Document Type: Job Description
Document Name: Cyber Security Associate
Date: June 2022
JD- Cyber Security Associate
Position: Cyber Security Associate
Job Title Cyber Security Associate
SHQ Business Division SecurityHQ
Location Pune, India
We are searching for a SOC Associate who will be responsible for monitoring, reporting, and
escalating events to our SOC Analysts.
Job Description The primary function of this position is to monitor the analytics tools and perform alert
management and initial incident qualification.
This role reports to the SOC Team Lead.
• Acknowledge, analyse and validate incidents triggered from correlated events through
SIEM solution
• Acknowledge, analyse and validate incidents received through other reporting
mechanisms such as email, phone calls, management directions, etc.
• Collection of necessary logs that could help in the incident containment and security
investigation
• Escalate validated and confirmed incidents to SOC Analyst
• Undertake first stages of false positive and false negative analysis
• Understand the structure and the meaning of logs from different log sources such as FW,
IDS, Windows DC, Cisco appliances, AV and antimalware software, email security etc.
Responsibilities
• Understand the subject of EDR alarms
• Open incidents in SecurityHQ (ITSM Platform) to report the alarms triggered or threats
detected. Analyst should properly include for each incident on SecurityHQ all details
related to the logs, alarms and other indicators identified in accordance with the
intervention protocol of each client and the SLA.
• Track and update incidents and requests based on client’s updates and analysis results
• Properly log client requests and change requests in SecurityHQ
• Report infrastructure issues to the SHQ support team.
• Report false positive alarms from EDR and SIEM to L2 SOC analysts
• Other duties related to the position
• Experience in Security Information Event Management (SIEM) tools.
Essential Skills • Should have expertise on TCP/IP network traffic and event log analysis
• Knowledge of ITIL disciplines such as Incident, Problem and Change Management
• Strong interpersonal and presentation skills
Additional Desired
• Ability to work with minimal levels of supervision or oversight
Skills
• Adherence to security policies
Education
Requirements & • Bachelor’s in Computer Science/IT/Electronics Engineering, M.C.A. or equivalent University
Experience degree
2 CONFIDENTIAL | ©2021 SecurityHQ Contact Us For more details visit
hr-india@[Link] [Link]
JD- Cyber Security Associate
• Minimum of 0- 1 year of experience in the IT security industry, preferably working in a
SOC/NOC environment
• Certifications: CCNA, CEH
3 CONFIDENTIAL | ©2021 SecurityHQ Contact Us For more details visit
hr-india@[Link] [Link]