Volexity logo
Volexity
Posted 70 days agoVerified live 1d ago

SOC Analyst

Brief overview

Remote
2+ yrsMinimum
Network protocolsOperating systemsThreat detectionThreat landscape knowledgeTTPs of threat actorsIndicators of compromiseIncident reportingAlert monitoring and triageSecurity operations center (SOC) experienceIncident response (IR)YARA signature writingSuricata signature writingMalware analysisDetection logic for EDR solutionsPython programmingGo programming

About the company

Volexity logo
Volexityvolexity.com

Volexity is a security firm that assists organizations with incident response, digital forensics, trusted advisory, and threat intelligence.

Job description

Summary

Volexity is a company focused on protecting organizations from various security threats. They are seeking a SOC Analyst to analyze and respond to advanced threats, collaborate with teams, and help protect targeted groups from cyber attacks.

Responsibilities

  • Monitoring and triaging alerts generated via network security monitoring, EDR platforms, and other log sources
  • Threat hunting across Volexity’s customer base to look for new or previously undetected threats
  • Creating detailed incident reports that provide context, as well as actionable recommendations and next steps
  • Assisting in the creation of detection content and alert signatures, as well as helping tune signatures as needed to improve detection accuracy
  • Working closely with customers, responding to inquiries and questions in a timely fashion
  • Tracking industry activity, such as new vulnerabilities and threat reports

Skills

  • Minimum of two years of experience in an IT Security focused role, specifically with a strong emphasis on investigating security incidents stemming from alerts generated by network intrusion detection systems, endpoint detection response/antivirus software, and logs generated from security devices and/or productivity suites (e.g., Microsoft 365, Google Workspace, etc.)
  • Excellent understanding of network protocols and operating systems as they relate to threat detection
  • Detailed knowledge of the current threat landscape and the TTPs of various threat actors
  • Ability to quickly determine the scope of a given threat detected, identifying indicators of compromise, and assessing the criticality of the threat to properly prioritize reporting and response
  • High-quality written communication skills, with the ability to document findings for customers in long-form reporting
  • Experience reviewing other team member's work to ensure high standards across the team
  • Resourceful self-starter who can work both with a team and independently, when required
  • Prior experience working a role where alert monitoring and triage was a primary responsibility
  • Prior experience working in a SOC or as part of an IR team responding to active threats, with an understanding of which facets of signatures can lead to false positives and how to avoid them
  • Prior experience working in a role that provided exposure to a diversity of organization networks and associated threats
  • Ability to write YARA and Suricata signatures; a successful candidate will be able to recognize the qualities of good signatures and create solid signatures for both the YARA and Suricata formats
  • Basic or higher proficiency in Malware Analysis
  • Ability to write detection logic for a variety of systems, such as SentinelOne, Microsoft Defender for Endpoint, or other endpoint detection and response solutions
  • Basic or higher proficiency in Python, Go, or a similar programming language

Qualifications

Must Haves

  • Minimum of two years of experience in an IT Security focused role, specifically with a strong emphasis on investigating security incidents stemming from alerts generated by network intrusion detection systems, endpoint detection response/antivirus software, and logs generated from security devices and/or productivity suites (e.g., Microsoft 365, Google Workspace, etc.)
  • Excellent understanding of network protocols and operating systems as they relate to threat detection
  • Detailed knowledge of the current threat landscape and the TTPs of various threat actors
  • Ability to quickly determine the scope of a given threat detected, identifying indicators of compromise, and assessing the criticality of the threat to properly prioritize reporting and response
  • High-quality written communication skills, with the ability to document findings for customers in long-form reporting
  • Experience reviewing other team member's work to ensure high standards across the team
  • Resourceful self-starter who can work both with a team and independently, when required

Nice to Haves

  • Prior experience working a role where alert monitoring and triage was a primary responsibility
  • Prior experience working in a SOC or as part of an IR team responding to active threats, with an understanding of which facets of signatures can lead to false positives and how to avoid them
  • Prior experience working in a role that provided exposure to a diversity of organization networks and associated threats
  • Ability to write YARA and Suricata signatures; a successful candidate will be able to recognize the qualities of good signatures and create solid signatures for both the YARA and Suricata formats
  • Basic or higher proficiency in Malware Analysis
  • Ability to write detection logic for a variety of systems, such as SentinelOne, Microsoft Defender for Endpoint, or other endpoint detection and response solutions
  • Basic or higher proficiency in Python, Go, or a similar programming language

More jobs like this