What are the responsibilities and job description for the Security Operations Center Analyst position at TekStream Solutions?
Splunk SOC Analyst 1 (on-call, as needed for shift coverage )
US Citizenship Required.
Location: US-based, remote.
We are seeking Security Operations Analysts, Tier 1 flex resources to fill-in for our full-time staff, as needed for shift coverage in our 24x7 SOC operations. This is ideal for someone working a full-time job who is looking to pick up extra shifts. Potential shifts are as follows:
Weekdays (M-F):
1st shift 8 am-4 pm
2nd shift 4 pm -12 am
3rd shift 12 am-8 am
Weekends (Saturday/Sunday-starts Friday at midnight):
4th shift: 12 am -12 pm
5th shift: 12 pm -12 am-hands over to 3rd shift Sunday night/Monday morning
______________________________________________________________
Role Responsibilities:
- Responsible for the first line of security incident coordination and response
- Investigation initiation for suspected security incidents
- Monitoring of security events and alerts received from Splunk/Splunk SOAR
- Managing end user reported incidents according to established run books and policies
- Initial event triage
- Initial ticketing (TekStream Jira)
- Escalation of incidents of a critical or high priority
- Daily report generation (turnover, activity, incident)
- Utilize pre-built dashboards to investigate events
- Insider threat case support
Skill Requirements:
- 1 year of work experience with a Bachelor’s or Advanced Degree
- Understanding and/or proven hands-on experience in security and SIEM-related concepts such as intrusion analysis and incident response
- Experience with Unix and Windows systems
- Knowledge and understanding of network protocols and devices
- Demonstrate problem solving, analytical skills and attention to detail.
- Ability to handle high pressure situations in a productive and professional manner
- Understanding of incident investigation, handling, and responses to incident documentation
- Ability to communicate effectively in English, verbally and in writing
Preferred Skills:
- Demonstrate background in a Security Operations Centre (SOC) ideal
- Packet and log analysis
- Familiarity with scripting (Bash, Python, Javascript)
- Preferred certifications include: Security , Network , CEH, MCSA, MCP or MCSE
- OS and/or network system administration skills and concepts around network configuration, segmentation, firewalls
- Anti-virus, Network Access Control, Encryption, Vulnerability Identification
- Familiarity with EDR tools (Crowdstrike, Defender, SentinelOne, etc.)
- Familiarity with Microsoft Azure administration