13 Sep
|
Plurilock
|
New South Wales
13 Sep
Plurilock
New South Wales
Job Description
SOC 2 Contract
n
Through 2026
n
Supporting APAC Time zones
n
Responsible for investigating security incidents and determining their root causes. They review incidents that have been escalated by Tier 1 analysts, who are responsible for collecting data and reviewing alerts. Tier 2/3 analysts use threat intelligence, such as indicators of compromise , TTPs, and company host system/network data sets to assess the alerts, threats and potential incidents in more depth.
n
They have deep experience with SIEM tools specifically Crowdstrike SIEM, network data, host data, Identity and Access log data, developing SIEM use cases, reducing/tuning false alerts and leading investigations until issues have been resolved. They will also monitor systems and events across different operating systems, such as Windows, macOS, and Linux.
n
Must be proactive, problem solver and curious.
n
Must have 5+ years recent experience as Tier 2 or 3 analyst at a large organization; government and Critical Infrastructure company preferred.
n
Must have strong, demonstrated SIEM and data correlation experience
n
Must have demonstrated experience designing new SOC use cases and working with vendor on implementing current use cases.
n
Must have experience designing and implementing runbooks and use cases to mitigate security incidents
n
Experience designing Incident Response plan, including alert definition, runbooks, escalation, etc..
n
Must have extensive experience reviewing and managing alerts in Microsoft Defender, Splunk and or Crowdstrike
n
Must have experience conducting hunts across disparate data sets, to include host data, vulnerability data, threat data, network data, active directory data, among others to identify threats
n
Experience leading timely security operations response efforts in collaboration with stakeholders
n
Experience documenting incident response communications for technical and management audiences
n
Must have experience setting up alert rules and effective alert management
n
Demonstrated ability to create runbooks and conducting investigations with key application, IT Infra and other stakeholders
n
Experience designing custom SOC SIEM use cases in Defender, Splunk and CRWD
n
Experience conducting forensic work investigations
n
Most be a problem solver
n
Must be curious
n
Must be analytical, qualitative and quantitative abilities
n
Must be adaptive to dynamic environment
n
Strong security operations documentation abilities
📌 SOC 2 Incident Response & SIEM Specialist (New South Wales)
🏢 Plurilock
📍 New South Wales