Associate SOC Engineer

Lahore, Punjab () 2 Positions

Job Description

  • Manage and optimize the performance of the SIEM and XDR solutions (Wazuh) to ensure effective security monitoring and incident detection.
  • Expertise in threat intelligence analysis, including the ability to identify, assess, and prioritize emerging threats to the organization.
  • Monitor and analyze trends, security logs, and alerts from Threat Prevention, firewalls, network appliances, Linux servers, Advance Web Application Firewalls, DDoS, API attacks, identity management, etc. to identify and mitigate security incidents.
  • Understand and analyze Palo Alto Networks Threat Detection capabilities to identify and respond to advanced threats.
  • Develop and maintain custom Yara rules for malware detection, leveraging Red Hat Insights and Bitdefender EDR for comprehensive malware protection.
  • Configure and maintain Security Onion for network traffic analysis, threat hunting, and incident response.
  • Integrate Dynatrace AppSec RAV and RAP to provide application-level security monitoring and vulnerability detection.
  • Manage and optimize Tenable Nessus for comprehensive vulnerability assessment and remediation.
  • Understand Cisco ESA and GTB DLP solutions to monitor data loss prevention (DLP) controls.
  • Enhance the usage of Syslog for centralized log management and UEBA for user and entity behavior analysis.
  • Utilize threat intelligence from various sources to proactively ingest, identify, analyze, and prioritize emerging threats, reducing the risk of successful cyberattacks.
  • Implement and maintain SOAR (Security Orchestration, Automation, and Response) capabilities to streamline incident response and security automation.
  • Ensure the organization's security posture aligns with the CIS Benchmark and other industry best practices.
  • Provide technical leadership and mentorship to the security operations team, sharing knowledge and best practices.
  • Collaborate with cross-functional teams to continuously improve the organization's overall security posture.
  • Participate in regular security reviews, incident response, and continuous improvement initiatives.
  • Strong automation skills, including the development of scripts and tools to automate repetitive tasks and enhance SOC workflow.
  • Conduct risk-based vulnerability assessments and penetration tests on network and applications.
  • Continuous review of Indicators of Attack (IoAs) and Indicators of Compromise (IoCs).

We are looking for

  • Education: Bachelor’s degree in cyber security
  • Experience: Fresh to 1 Year

Skills

  1. Knowledge of Kali Linux, IDS/IPS, firewall, threat intelligence platforms, threat hunting, SOAR, Automation, and other security products.
  2. Strong critical thinking and problem-solving skills.
  3. Passion for information and data security.
  4. Detail oriented with strong organization skills.
  5.  

Tools

  • Security Information Event Management (SIEM) tools

Learn more about i2c

Explore our latest press releases, media coverage, industry events and thought leadership content that reveal how we’re outpacing the competition and shaping what's next.

Ignite Your Curiosity