SOC Analyst

Ampcus IncChicago, United States
Full TimeOn-siteMidLimited info disclosed
8 views0 applications

Description

Ampcus Inc. is a certified global provider of a broad range of Technology and Business consulting services. We are in search of a highly motivated candidate to join our talented Team. Job Title: SOC Analyst Location(s): Chicago, IL (Remote) Position Summary The SOC Analyst provides operational support for the Security Operations Center, Security Information and Event Management (SIEM), and other enterprise security services. The analyst is responsible for monitoring, analyzing, triaging, investigating, and escalating security alerts and incidents while meeting defined security incident response SLAs. Key Responsibilities Monitor SIEM platforms through daily review and analysis of security alerts. Perform initial incident response activities, including anomaly identification, alert triage, investigation, documentation, and escalation. Monitor Data Loss Prevention (DLP) alerts and perform initial investigation, triage, and escalation. Monitor Cloud Access Security Broker (CASB) alerts and investigate potential security events. Monitor Next-Generation Antivirus (NGAV) alerts and perform initial analysis and escalation as required. Monitor reported spam and phishing emails, conduct basic investigations, quarantine malicious messages, and escalate confirmed incidents. Meet defined security incident SLAs, including Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR). Correlate security events and data from multiple sources to identify potential threats and security incidents. Support security systems and services in accordance with organizational Information Security Program policies and standards. Identify and resolve potential and actual security issues by staying current with security threats, vulnerabilities, technologies, and best practices. Protect information systems by supporting access controls, security configurations, and control structures. Identify abnormal activity, recognize security violations, and report potential incidents. Assess existing security controls and recommend improvements based on current threats, trends, and operational requirements. Participate in periodic security audits and investigations to identify violations, vulnerabilities, and inefficiencies. Perform other security-related duties as assigned. Required Skills And Knowledge 2-4 years of experience as a SOC Analyst or in a comparable Information Security/NOC/SOC role. Hands-on experience with security incident triage, investigation, analysis, and escalation. Strong knowledge of Splunk. Experience with Tanium. Experience with CrowdStrike. Experience with AWS Cloud Security. Experience monitoring and analyzing security incidents from multiple data sources. Ability to correlate security events from sources such as: User authentication events Windows security event logs Syslog NetFlow/PCAP DHCP and DNS logs Intrusion detection alerts Proxy logs Packet captures Firewall events Understanding of Windows, Linux, and network security concepts and common attack/compromise techniques. Knowledge of Microsoft Active Directory, Group Policy, DNS, Certificate Services, and DHCP. Solid understanding of IP networking fundamentals, including IPv4, TCP/IP, LAN/WAN concepts, routing, NAT, and ACLs. Knowledge of security methodologies, processes, and technical security solutions. Experience with SIEM, DLP, NGAV, vulnerability scanning, URL filtering, and email security technologies. Ability to communicate effectively within a technical security environment. Strong analytical, critical-thinking, problem-solving, judgment, and decision-making skills. Preferred Skills Python and/or PowerShell scripting. Cyber forensics concepts, including malware analysis and threat hunting. Previous enterprise SOC experience. Familiarity with cloud security concepts, particularly AWS. Experience with security incident response and investigation processes. Education Associate degree in Computer Information Systems, Cybersecurity, Computer Science, or a related field. Preferred Certifications CompTIA Security+ CompTIA Network+ GIAC Security Essentials (GSEC) GIAC Information Security Fundamentals (GISF) Nice to Have AWS Certified Cloud Practitioner (AWS CCP) Microsoft Azure Fundamentals (AZ-900) Governance, Risk & Compliance Familiarity with security governance and compliance frameworks, standards, and regulations, including: HIPAA PCI-DSS ISO NIST SOX GDPR CCPA NAIC Core Competencies Reading Comprehension Critical Thinking Complex Problem Solving Effective Verbal Communication Technical Writing Judgment and Decision Making Time Management Service Orientation Ampcus is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veterans or individuals with disabilities.