We are seeking a detail-oriented and proactive SOC Analyst in Lahore to join our Cybersecurity team. The SOC Analyst will be responsible for continuously monitoring security events, investigating incidents, responding to cyber threats, and helping protect the organization’s networks, systems, and data. The ideal candidate has experience with SIEM platforms, endpoint security tools, threat intelligence, and incident response processes. This role requires strong analytical skills, attention to detail, and the ability to work effectively in a fast-paced Security Operations Center environment.
Key Responsibilities:
- Monitor security alerts and events using Security Information and Event Management (SIEM) platforms.
- Investigate, triage, and respond to security incidents, including malware infections, phishing attacks, unauthorized access, and suspicious network activity.
- Analyze logs from endpoints, firewalls, IDS/IPS, servers, cloud platforms, and network devices.
- Perform initial incident response activities, including containment, eradication, and recovery support.
- Escalate complex security incidents to senior analysts or incident response teams as needed.
- Conduct threat hunting activities to proactively identify potential security threats.
- Review and correlate security events to identify patterns of malicious activity.
- Maintain and improve SIEM use cases, detection rules, and alert tuning.
- Collaborate with IT, Cloud, Infrastructure, and Engineering teams to remediate security vulnerabilities.
- Support vulnerability management by validating findings and tracking remediation efforts.
- Assist with digital forensics investigations and evidence collection.
- Generate incident reports and provide recommendations to improve security posture.
- Stay current with emerging cyber threats, vulnerabilities, attack techniques, and industry best practices.
- Participate in 24/7 SOC operations, including rotating on-call or shift schedules if required.
Required Qualifications:
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field (or equivalent experience).
- 2+ years of experience in a Security Operations Center (SOC), Cybersecurity, or Incident Response role.
- Experience working with SIEM platforms such as Microsoft Sentinel, Splunk, IBM QRadar, LogRhythm, Elastic Security, or ArcSight.
- Knowledge of Windows, Linux, and Active Directory security.
- Experience with endpoint detection and response (EDR) tools such as Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, or Carbon Black.
- Understanding of TCP/IP, DNS, HTTP/HTTPS, VPNs, and network security concepts.
- Familiarity with IDS/IPS technologies and firewall management.
- Knowledge of common cyber threats, malware, ransomware, phishing, and attack techniques.
- Understanding of the MITRE ATT&CK Framework and Cyber Kill Chain.
- Experience analyzing system, application, and network logs.
- Familiarity with cloud security concepts (AWS, Azure, or Google Cloud).
- Strong troubleshooting, analytical, and communication skills.