Be the first to apply!

Lead SoC Analyst

GSS HR Solutions Pvt LTD   pin Colombo - Full-time

Key responsibilities & Accountabilities:
* Advanced Incident Response & Threat Investigation
Investigate and remediate escalated security incidents involving advanced attack techniques.
Perform detailed forensic data collection, root cause analysis, and system restoration.

* Mentorship & Knowledge Sharing
Provide guidance and mentorship to L1 analysts on investigation techniques, escalation workflows, and threat
mitigation strategies.
Conduct knowledge-sharing sessions within the SOC to improve detection capabilities.
* Inter-Team Collaboration & Documentation
Work alongside IT, engineering, and compliance teams to enhance security workflows and response plans.
Develop training materials and process documentation to support cross-functional security initiatives.
* Advanced Security Stack Management & Optimization
Conduct advanced tuning of security detection tools to enhance accuracy and reduce false positives.
Address complex tuning requests escalated from L1 analysts.
* Threat Hunting & Proactive Security Analysis
Perform in-depth analysis of suspicious activities to uncover and mitigate hidden security threats.
Conduct intermediate-level threat hunting, focusing on host artifacts, domain patterns, and network anomalies.
* Intermediate Detection Engineering
Develop detection rules and mechanisms to address network and host-based threats.
* Security Tools Proficiency & Continuous Improvement
Utilize and manage SIEM, EDR, XDR, vulnerability scanners, firewalls, and email gateways at an intermediate level.
* Reporting, Documentation & Stakeholder Communication
Create detailed security reports on incidents, emerging threats, and SOC operational performance
* 24x7 SOC Operations & Leadership Support
Maintain operational readiness in a 24/7 SOC environment, ensuring effective incident management and response
during all shifts.
Act as a point of escalation for complex security events, providing guidance to junior analysts and ensuring smooth
SOC operations.
Contribute to continuous improvement efforts, refining SOC workflows and enhancing detection capabilities.
Skills & Ability
Technical Skills
Strong understanding of security frameworks, attack tactics (MITRE ATT&CK), and defensive security operations.
Proficiency in security monitoring tools (SIEM, EDR, XDR, vulnerability scanners, firewalls, IDS/IPS).
Experience with log analysis, forensic investigation techniques, and security event correlation.
Ability to analyze malicious activity across endpoints, networks, and cloud environments.
Soft Skills
Strong problem-solving skills with the ability to investigate and resolve complex security incidents.
Excellent written and verbal communication for effective documentation and reporting.
Ability to work in high-pressure environments, multitask, and adapt to evolving cybersecurity challenges
Educational Qualifications
3+ years of experience in SOC operations, cybersecurity analysis, or incident response.
Bachelors degree in Cybersecurity, Computer Science, or related field, OR equivalent hands-on experience.
Security certifications such as CompTIA CASP+, Pentest+, eCTHP, BTL2, GCIH, or similar are a plus.
 Qualifications 

  • Technical Skills
    • Strong understanding of:
      • Security frameworks (e.g., MITRE ATT&CK)
      • Defensive security operations
    • Proficient with:
      • SIEM, EDR, XDR
      • Vulnerability scanners
      • Firewalls
      • IDS/IPS
    • Experienced in:
      • Log analysis
      • Forensic investigation techniques
      • Security event correlation
    • Capable of analyzing malicious activity across:
      • Endpoints
      • Networks
      • Cloud environments
  • Soft Skills
    • Strong problem-solving and analytical skills.
    • Excellent written and verbal communication.
    • Able to work in high-pressure environments and adapt to evolving cyber threats.
    • Capable of multitasking and managing multiple priorities effectively.

🎓 Educational Qualifications

  • 3+ years of experience in:
    • SOC operations
    • Cybersecurity analysis
    • Incident response
  • Bachelor's degree in:
    • Cybersecurity
    • Computer Science
    • Related field
    • OR equivalent hands-on experience
  • Preferred certifications (a plus):
    • CompTIA CASP+
    • Pentest+
    • eCTHP
    • BTL2
    • GCIH
    • Or similar
Share Share Report Report Go Back to Category Information Technology time Posted on 11 Oct 2025 Viewed Viewed 4 times