A
SOC Security Analyst
Amprion
On-site Mid Level 6d ago
About the role
About
At the Pulheim site, IT/OT systems are monitored around the clock in a SOC watch. This includes permanent monitoring of running systems as well as the analysis and processing of security incidents. Security analysts in the SOC are responsible for the detection and initial analysis of security incidents. They also coordinate resolution measures with specialists in the back office and the business units. Furthermore, security analysts work on the continuous improvement of monitoring in the SIEM platform. In addition, security analysts take on other tasks in the area of operational IT security.
Responsibilities
- Monitoring of the company's IT and OT infrastructure
- Monitoring and initial analysis of security incidents in a SIEM
- Triage of security incidents
- Resolution of known security incidents using playbooks
- Documentation and escalation of security incidents
- Further analysis of security incidents together with the back office and the business units
- Participation in the continuous improvement of monitoring
- Carrying out further operational tasks in the area of operational IT security, such as darknet monitoring, vulnerability management, and cyber threat intelligence
Requirements
- Completed vocational training as an IT specialist or comparable qualification or relevant professional experience in the mentioned field
- 2-3 years of professional experience in the above-mentioned area of responsibility are desirable
- Ideally, practical experience or certifications in the following areas:
- SIEM solutions, such as Splunk ES
- Security components, such as IDS, firewalls, routers, endpoint protection
- Security certifications, such as Splunk Certified Cybersecurity Defense Analyst, CompTIA CySA+, CCNA Security
- Experience in the network environment and understanding of attack methods against applications, systems, and networks
- Very good German skills and good English skills
- Communication and teamwork skills as well as a high degree of personal responsibility
- Shift work (24/7)
Requirements
- Erfahrungen im Netzwerkumfeld und Verständnis von Angriffsmethoden gegen Applikationen, Systeme und Netzwerke
- Sehr gute Deutschkenntnisse und gute Englischkenntnisse
- Kommunikations- und Teamfähigkeit sowie ein hohes Maß an Eigenverantwortung
Responsibilities
- Überwachung der IT- und OT-Infrastruktur des Unternehmens
- Monitoring und Erstanalyse von Security Incidents in einem SIEM
- Einstufung (Triage) von Security Incidents
- Behebung von bekannten Security Incidents anhand von Playbooks
- Dokumentation und Eskalation von Security Incidents
- Weitergehende Analyse von Security Incidents zusammen mit dem Backoffice und den Fachbereichen
- Mitarbeit bei der kontinuierlichen Verbesserung des Monitorings
- Durchführung weiterer operativer Aufgaben im Bereich der operativen IT-Security, wie im Bereich Darknet-Monitoring, Vulnerability Management, Cyber Threat Intelligence
Skills
CCNA SecurityCompTIA CySA+Endpoint ProtectionFirewallsIDSRouterSIEMSplunk ESSplunk Certified Cybersecurity Defense Analyst
Don't send a generic resume
Paste this job description into Mimi and get a resume tailored to exactly what the hiring team is looking for.
Get started free