We are seeking a skilled Security Operations Centre (SOC) Analyst to join our team and play a critical role in protecting our organization from cyber threats. The SOC Analyst will be responsible for monitoring, detecting, analysing, and responding to security incidents and events, ensuring the integrity, confidentiality, and availability of our solutions and data. You will play a pivotal role in ensuring compliance with Thinkproject's regulatory compliance standards across all platforms.
The SOC Analyst will be a key player in building and operating our cybersecurity operations, providing real-time analysis and investigation of potential security threats. They will collaborate with cross-functional teams to investigate threats, take remedial action, and resolve any security concerns.
The ideal candidate will have knowledge and experience of working in a Security Operations Centre (SOC), with expertise in introducing and managing logging solutions, particularly Security Information and Event Management (SIEM) systems. They should be capable of providing oversight, expert guidance, and support within a security operations team.
The role will involve handling both reactive responses to security incidents of varying criticality and proactive measures to enhance the organization’s security posture. Familiarity with cloud platforms such as Azure and AWS is advantageous.
The SOC Analyst will also be responsible for monitoring the health of Thinkproject's IT network infrastructure, responding to health-related events using the same high-level structure applied to cybersecurity events.
This role will work within our Product and Central IT organizational branch, under direction of the Director of Cyber Security and Networking.
- Continuously monitor security events using a variety of tools (e.g., SIEM, IDS/IPS, firewalls) to identify potential threats, anomalies, vulnerabilities, and incidents.
- Investigate and respond to security events and incidents, ensuring timely identification, containment, eradication, and recovery from threats. Document and report incidents in line with existing policies
- Conduct forensic analysis of cybersecurity events, ensuring that all documentation meets legal standards.
- Conduct regular security checks on key systems to monitor for issues and indications of compromise
- Proactively hunt for threats using threat feeds and advanced analysis to understand emerging threats and vulnerabilities. Provide insights and recommendations to mitigate risks.
- Arrange and oversee frequent penetration tests of our solutions, ensuring they are conducted successfully and without impacting service.
- Manage the output of security issues from cyber security assessment tools, coordinating with key stakeholders to ensure timely mitigation and remediation of identified issues and threats.
- Assist in developing and implementing cybersecurity policies, procedures, monitoring and response solutions.
- Ensure all security operations are conducted in compliance with relevant regulatory requirements, industry standards, and internal policies. Assist in the preparation and maintenance of audit and compliance documentation.
- Prepare detailed internal and customer facing reports on security incidents, vulnerabilities, posture and compliance status for management, stakeholders and customers.
- Develop and implement event response procedures and playbooks
- Participate in and develop security assessment exercises to evaluate operational effectiveness.
- Contribute to the ongoing maturation of the Security Operations Centre by introducing new logging, monitoring, and response solutions to enhance departmental operations and improve cybersecurity coverage.
- Adapt SOC processes, solutions, and procedures to enhance the monitoring of the organization's IT network health.