Be the first to apply!
Lead SoC Analyst
GSS HR Solutions Pvt LTD
Colombo -
Full-time
Key responsibilities & Accountabilities:
* Advanced Incident Response & Threat Investigation
Investigate and remediate escalated security incidents involving advanced attack techniques.
Perform detailed forensic data collection, root cause analysis, and system restoration.
* Mentorship & Knowledge Sharing
Provide guidance and mentorship to L1 analysts on investigation techniques, escalation workflows, and threat
mitigation strategies.
Conduct knowledge-sharing sessions within the SOC to improve detection capabilities.
* Inter-Team Collaboration & Documentation
Work alongside IT, engineering, and compliance teams to enhance security workflows and response plans.
Develop training materials and process documentation to support cross-functional security initiatives.
* Advanced Security Stack Management & Optimization
Conduct advanced tuning of security detection tools to enhance accuracy and reduce false positives.
Address complex tuning requests escalated from L1 analysts.
* Threat Hunting & Proactive Security Analysis
Perform in-depth analysis of suspicious activities to uncover and mitigate hidden security threats.
Conduct intermediate-level threat hunting, focusing on host artifacts, domain patterns, and network anomalies.
* Intermediate Detection Engineering
Develop detection rules and mechanisms to address network and host-based threats.
* Security Tools Proficiency & Continuous Improvement
Utilize and manage SIEM, EDR, XDR, vulnerability scanners, firewalls, and email gateways at an intermediate level.
* Reporting, Documentation & Stakeholder Communication
Create detailed security reports on incidents, emerging threats, and SOC operational performance
* 24x7 SOC Operations & Leadership Support
Maintain operational readiness in a 24/7 SOC environment, ensuring effective incident management and response
during all shifts.
Act as a point of escalation for complex security events, providing guidance to junior analysts and ensuring smooth
SOC operations.
Contribute to continuous improvement efforts, refining SOC workflows and enhancing detection capabilities.
Skills & Ability
Technical Skills
Strong understanding of security frameworks, attack tactics (MITRE ATT&CK), and defensive security operations.
Proficiency in security monitoring tools (SIEM, EDR, XDR, vulnerability scanners, firewalls, IDS/IPS).
Experience with log analysis, forensic investigation techniques, and security event correlation.
Ability to analyze malicious activity across endpoints, networks, and cloud environments.
Soft Skills
Strong problem-solving skills with the ability to investigate and resolve complex security incidents.
Excellent written and verbal communication for effective documentation and reporting.
Ability to work in high-pressure environments, multitask, and adapt to evolving cybersecurity challenges
Educational Qualifications
3+ years of experience in SOC operations, cybersecurity analysis, or incident response.
Bachelors degree in Cybersecurity, Computer Science, or related field, OR equivalent hands-on experience.
Security certifications such as CompTIA CASP+, Pentest+, eCTHP, BTL2, GCIH, or similar are a plus. Qualifications
- Technical Skills
- Strong understanding of:
- Security frameworks (e.g., MITRE ATT&CK)
- Defensive security operations
- Proficient with:
- SIEM, EDR, XDR
- Vulnerability scanners
- Firewalls
- IDS/IPS
- Experienced in:
- Log analysis
- Forensic investigation techniques
- Security event correlation
- Capable of analyzing malicious activity across:
- Endpoints
- Networks
- Cloud environments
- Strong understanding of:
- Soft Skills
- Strong problem-solving and analytical skills.
- Excellent written and verbal communication.
- Able to work in high-pressure environments and adapt to evolving cyber threats.
- Capable of multitasking and managing multiple priorities effectively.
🎓 Educational Qualifications
- 3+ years of experience in:
- SOC operations
- Cybersecurity analysis
- Incident response
- Bachelor's degree in:
- Cybersecurity
- Computer Science
- Related field
- OR equivalent hands-on experience
- Preferred certifications (a plus):
- CompTIA CASP+
- Pentest+
- eCTHP
- BTL2
- GCIH
- Or similar