06 Oct
|
Plurilock
|
Sydney
Job Description
Position Overview n
SOC 2 Contract through 2026 Supporting APAC Time zones.
Responsibilities n
n
- Investigate security incidents and determine root causes.
n
- Review incidents escalated by Tier 1 analysts, who collect data and review alerts.
n
- Utilize threat intelligence—including indicators of compromise (IoCs), tactics, techniques, and procedures (TTPs), and company host, network data sets—to assess alerts, threats, and potential incidents in depth.
n
- Develop and refine SIEM use cases, reduce/tune false alerts, and lead investigations until issues are resolved.
n
- Monitor systems and events across Windows, macOS, and Linux operating systems.
n
Qualifications nn
- Proactive, problem‑solver, and curious.
n
- 5+ years recent experience as a Tier 2 or Tier 3 analyst at a large organization; preference for government and critical‑infrastructure companies.
n
- Strong, demonstrated SIEM and data correlation experience.
n
- Experience designing current SOC use cases and working with vendors to implement them.
n
- Experience designing and implementing runbooks to mitigate security incidents.
n
- Experience designing incident‑response plans,
including alert definitions, runbooks, and escalation procedures.
n
- Extensive experience reviewing and managing alerts in Microsoft Defender, Splunk, and/or CrowdStrike.
n
- Proficient in conducting hunts across disparate data sets—host, vulnerability, threat, network, and Active Directory data—to identify threats.
n
- Leadership in timely security‑operations response efforts in collaboration with stakeholders.
n
- Documentation of incident‑response communications for technical and management audiences.
n
- Ability to set up alert rules and manage alerts effectively.
n
- Demonstrated ability to create runbooks and conduct investigations with key application, IT infrastructure, and other stakeholders.
n
- Experience designing custom SOC SIEM use cases in Defender, Splunk, and CrowdStrike.
n
- Experience conducting forensic investigations.
n
- Analytical, qualitative, and quantitative abilities.
n
- Adaptive to dynamic environment.
n
- Strong security‑operations documentation abilities.
n
n
#J-18808-Ljbffr
📌 SOC 2 Analyst (Sydney)
🏢 Plurilock
📍 Sydney