SOC Analyst - L1
Teknik, data och digitalt · IT-infrastruktur och säkerhet · Cybersäkerhet
I korthet
As a SOC Analyst (L1/L2) at Accenture in Kuwait City, you will be responsible for continuous monitoring, detection, analysis, and response to cybersecurity threats. This full-time, early-career role involves real-time security event monitoring, incident triage, investigation, and remediation to ensure 24x7 SOC operations.
Ansvarsområden
- Monitor and analyze security alerts from SIEM, SOAR, EDR, and other security tools to identify potential threats.
- Perform timely triage, validation, and investigation of alerts in accordance with SLA and prioritization matrix (P1–P4).
- Execute approved containment, response, and remediation actions using defined SOC runbooks.
- Manage incidents through the full case lifecycle, ensuring accurate documentation, status updates, and closure in the case management system.
- Follow standard case handling processes, including case stage/status flow and QA validation requirements.
- Monitor SOC communication channels (e.g., mailbox, SOAR) and ensure timely response to inquiries, escalations, and stakeholder coordination.
- Escalate high-severity or complex incidents in line with SLAs, including immediate notification for potential P1/P2 cases.
- Ensure SLA compliance and resolution, including coordination with internal and external stakeholders.
- Perform shift-based operations, including effective handover of active and critical cases with complete context.
- Identify and report operational issues, anomalies, or delays within the same shift to relevant leads.
- Support continuous improvement by identifying gaps in detection, logging, automation, and case handling processes.
Krav
- Strong understanding of cybersecurity fundamentals, including threat types, attack vectors, the CIA triad, and awareness of frameworks such as MITRE ATT&CK for threat identification.
- Working knowledge of operating systems (Windows, Linux/Unix) and networking concepts (TCP/IP, OSI model, DNS, HTTP/S).
- Experience or familiarity with SIEM/SOAR platforms, endpoint protection, firewalls, and security monitoring tools.
- Ability to analyze logs, network traffic, and endpoint telemetry to identify malicious activity.
- Bachelor’s degree in computer science, Information Security, Information Technology, or a related field.
- 1–3 years of experience in Security Operations, IT security, or a related role.
- Basic understanding of cybersecurity concepts, threats, and attack methodologies.
- Familiarity with incident handling, alert triage, and case management processes.
- Strong analytical and problem-solving skills with attention to detail.
- Good written and verbal communication skills for documentation and handover reporting.
Önskade kvalifikationer
- Exposure to cloud security concepts (Azure, AWS, or GCP) is an advantage.
- Familiarity with the MITRE ATT&CK framework for threat identification is an advantage.
- Hands-on exposure or academic experience with SIEM, SOAR, EDR, or security monitoring tools is an advantage.
- Relevant certifications – e.g., Security+, SC-200, CEH (Associate level) – are an advantage but not mandatory.
Förmåner
- Opportunities to keep skills relevant through certifications, learning, and diverse work experiences.
- Consistently recognized as one of the World’s Best Workplaces™.
#cybersecurity#SOC#security operations#threat detection#incident response