What are the responsibilities and job description for the SOC Engineer position at Valor Benefit Services?
As a SOC Analyst, you will serve as the first line of defense in protecting our organization's digital assets. You will monitor security logs, analyze network traffic for anomalies, and investigate potential security breaches. The ideal candidate possesses a strong foundation in cybersecurity principles, experience with Security Information and Event Management (SIEM) tools, and a proactive approach to threat detection and incident response.
Key Responsibilities
-
Continuous Monitoring: Monitor security dashboards and alerts (SIEM, EDR, NDR) 24/7 to identify suspicious activities or potential cyberattacks.
-
Incident Investigation: Perform initial triage on security alerts to determine if they are false positives or genuine security incidents.
-
Incident Response: Execute established playbooks to contain, eradicate, and recover from confirmed security threats.
-
Threat Intelligence: Analyze logs, packet captures, and intelligence feeds to identify indicators of compromise (IoCs) and stay updated on emerging threat landscapes.
-
Documentation: Maintain meticulous records of security incidents, investigation steps, and resolution details within the ticketing system.
-
Process Improvement: Assist in the development and refinement of incident response playbooks and automation scripts to reduce mean time to respond (MTTR).
Required Technical Skills
-
SIEM Platforms: Proficiency with tools such as Splunk, Microsoft Sentinel, or IBM QRadar.
-
Security Tools: Hands-on experience with Endpoint Detection and Response (EDR) agents (e.g., CrowdStrike, SentinelOne) and vulnerability scanners.
-
Networking: Strong understanding of TCP/IP, DNS, HTTP/HTTPS, VPNs, and firewall architectures.
-
Operating Systems: Intermediate to advanced knowledge of Windows, Linux, and macOS internals.
-
Scripting: Basic proficiency in Python, PowerShell, or Bash for automating log parsing and data collection.
Qualifications & Certifications
-
Experience: 1–3 years of experience in an IT security, network administration, or SOC environment.
-
Education: Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent professional experience).
-
Preferred Certifications: CompTIA Security , CySA , BTL1, GCIH, or Cisco Certified CyberOps Associate.
Key Competencies
-
Critical Thinking: Ability to analyze complex data sets and connect disparate events to form a clear picture of an attack.
-
Calm Under Pressure: Ability to remain composed and follow established procedures during high-stress security incidents.
-
Effective Communication: Ability to translate complex technical findings into clear updates for non-technical stakeholders.
Visualizing the SOC Ecosystem
The SOC workflow generally follows a standard lifecycle where incoming data is processed, monitored, and acted upon.
Collection: Ingesting logs from firewalls, servers, and applications.
Detection: Correlating data to identify potential threats or policy violations.
Response: Executing playbooks to mitigate the impact of an identified incident.