- Company Name
- SILICOM SAS
- Job Title
- Analyste SOC
- Job Description
-
**Job Title:** SOC Analyst
**Role Summary:**
Perform security monitoring, detection, and incident response within a Security Operations Center (SOC) focusing on Splunk and automation. Develop queries, dashboards, and playbooks to improve threat detection, reduce mean‑time‑to‑response (MTTR), and minimize manual effort.
**Expectations:**
- Minimum 1 + year experience in a SOC environment.
- Bachelor’s/Master’s (Bac+5) degree in Cybersecurity, Computer Science, or Information Systems.
- Ability to work autonomously, communicate clearly, and collaborate with cross‑functional teams.
**Key Responsibilities:**
- Operate and maintain Splunk: create/optimize SPL queries, security correlations, dashboards, and alerts.
- Conduct tiered (N1‑N3) investigations: log analysis, timeline building, IOC handling, post‑incident review.
- Analyze security events from EDR, firewalls, proxies, IAM, AD, and cloud platforms (AWS/Azure/GCP).
- Develop and maintain automation scripts (PowerShell, Bash) for alert enrichment, automatic response actions, and log normalization.
- Integrate Splunk with third‑party tools (EDR, firewalls, ITSM, REST APIs).
- Contribute to incident response playbooks and SOAR processes to lower MTTR.
**Required Skills:**
*Hard Skills*
- Proficient with Splunk (queries, dashboards, alerts).
- Solid understanding of SOC concepts: SIEM, SOAR, EDR, IDS/IPS.
- Knowledge of common attack techniques (malware, phishing, brute‑force, lateral movement, data exfiltration).
- Strong scripting abilities in PowerShell and Bash.
*Soft Skills*
- Service‑oriented mindset with strong pedagogical skills.
- High level of rigor, autonomy, and analytical capability.
- Clear, structured communication.
- Team player, proactive, adaptable to diverse teams.
**Required Education & Certifications:**
- Bac+5 (Master’s) in Cybersecurity, Computer Science, Information Systems, or related field.
- Relevant certifications are optional but beneficial (e.g., ISO 27001, EBIOS RM, Cloud security, DevSecOps).