Security Operations Center (SOC) Analyst
9000 - 12.9k PLN9000 - 12 900 PLN/ mies.UoP
MidFull-time·Umowa o pracę
#448864·Dodano 2 dni temu·1
Źródło: nofluffjobs.comTech Stack / Keywords
SecurityEDRCybersecurityDegree
Firma i stanowisko
Grant Thornton Capability Center Poland is hiring for a SOC Analyst role within a tierless SOC model operating a follow-the-sun security operations team.
Wymagania
- Minimum 2 years of experience in security operations, SOC monitoring, SIEM operations, EDR, MDR, incident response, or related cybersecurity roles.
- Experience working in SOC, MDR, MSSP, or enterprise security operations environments.
- Hands-on experience with CrowdStrike Falcon Next-Gen SIEM and EDR strongly preferred.
- Experience with ServiceNow or similar ITSM/security case management platforms.
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or related discipline preferred; equivalent practical experience considered.
- Preferred certifications: CrowdStrike Certified SIEM Analyst (CCSA), CompTIA CySA+, other SOC/SIEM/incident response/network security/digital forensics certifications.
- Strong hands-on information security skills, incident investigation, and analytical reasoning.
- Ownership mindset, attention to detail, and solid understanding of MITRE ATT&CK and incident response lifecycle.
- Excellent written/verbal communication skills and ability to brief technical and non-technical stakeholders.
- Strong organization, time management, calm decision-making under pressure, ability to work independently and in teams.
Obowiązki
Security Monitoring & Alert Triage:
- Use CrowdStrike Falcon Next-Gen SIEM for real-time monitoring, analysis, detection review, event correlation, case management, and reporting.
- Review, prioritize, and classify alerts according to severity and SOC procedures.
- Determine whether alerts are false positives, benign, suspicious, policy violations, or security incidents.
- Conduct triage, detailed investigations, evidence review, response coordination, and documentation.
- Analyze first-party and third-party detections and correlation rule outputs.
- Maintain accurate triage decisions and updates in incident management.
Incident Response & Remediation:
- Handle incidents promptly following SOC runbooks, escalation workflows, and operational expectations.
- Execute Cybersecurity Incident Response Plan activities and SOC playbooks.
- Support containment, eradication, and recovery with IT resolver teams and other security units.
- Escalate major incidents to CSIRT or management when appropriate.
- Assist with root cause analysis documentation for major or repeat incidents.
Threat Analysis & Continuous Improvement:
- Support threat hunting, detection validation, and investigations using Falcon Next-Gen SIEM.
- Identify vulnerabilities, threats, exploits, and security control weaknesses.
- Create visualizations, summaries, and reports for SOC leadership and stakeholders.
- Recommend improvements to detection logic, correlation rules, dashboards, alert handling, and runbooks.
- Review threat intelligence advisories and indicators of compromise.
- Support SOC metrics, quality checks, reporting, and continuous improvement.
- Support audit, compliance, and evidence requests as needed.
Shift & Operational Requirements:
- Operate in a 24x7 SOC and incident response environment.
- Handle full lifecycle activities including triage, investigation, escalation, and closure.
- Communicate clearly with technical teams, management, legal, and privacy teams.
- Follow structured incident response, evidence handling, reporting, and documentation practices.
Benefity
- Hybrid working model: 2 days in the office (Poznań, Malta Office Park) and 3 days remote.
- Stable employment with an employment contract (umowa o pracę), private medical care.
- Benefits package including MultiSport and a benefits platform.
- International environment collaborating with experienced experts.
- Teamwork-based culture with trust and knowledge sharing.
- Well-structured onboarding program.
- Clear career development paths with learning and certification programs.
- Access to training platforms and professional growth tools.
- Inclusive workplace welcoming people with disabilities.
- Modern office in Poznań.
- Fluency required in Polish and English.
- Additional perks: sport_subscription, private_health_care, training budget, free coffee, bicycle parking, mobile phone, in-house trainings.
Karta sportowa
Opieka zdrowotna
Dofinansowanie szkoleń
Napoje w biurze
Parking dla rowerów
Telefon
Szkolenia wewnętrzne
Grant Thornton Capability Center Poland
12 aktywnych ofert