06 Aug
|
Plurilock
|
City of Sydney
06 Aug
Plurilock
City of Sydney
Position Overview
SOC 2 Contract through 2026 Supporting APAC Time zones.
Responsibilities
- Investigate security incidents and determine root causes.
- Review incidents escalated by Tier 1 analysts, who collect data and review alerts.
- Utilize threat intelligence—including indicators of compromise (IoCs), tactics, techniques, and procedures (TTPs), and company host, network data sets—to assess alerts, threats, and potential incidents in depth.
- Develop and refine SIEM use cases, reduce/tune false alerts, and lead investigations until issues are resolved.
- Monitor systems and events across Windows, macOS, and Linux operating systems.
Qualifications
- Proactive, problem‑solver, and curious.
- 5+ years recent experience as a Tier 2 or Tier 3 analyst at a large organization; preference for government and critical‑infrastructure companies.
- Strong, demonstrated SIEM and data correlation experience.
- Experience designing new SOC use cases and working with vendors to implement them.
- Experience designing and implementing runbooks to mitigate security incidents.
- Experience designing incident‑response plans,
including alert definitions, runbooks, and escalation procedures.
- Extensive experience reviewing and managing alerts in Microsoft Defender, Splunk, and/or CrowdStrike.
- Proficient in conducting hunts across disparate data sets—host, vulnerability, threat, network, and Active Directory data—to identify threats.
- Leadership in timely security‑operations response efforts in collaboration with stakeholders.
- Documentation of incident‑response communications for technical and management audiences.
- Ability to set up alert rules and manage alerts effectively.
- Demonstrated ability to create runbooks and conduct investigations with key application, IT infrastructure, and other stakeholders.
- Experience designing custom SOC SIEM use cases in Defender, Splunk, and CrowdStrike.
- Experience conducting forensic investigations.
- Analytical, qualitative, and quantitative abilities.
- Adaptive to agile environment.
- Strong security‑operations documentation abilities.
#J-18808-Ljbffr
📌 SOC 2 Analyst (City of Sydney)
🏢 Plurilock
📍 City of Sydney