Security Operations / SOC Analyst
APAR TECHNOLOGIES PTE. LTD.
Key Responsibilities
- Monitor and investigate security alerts and incidents.
- Analyse security events using SIEM, EDR/XDR, identity, email, cloud and network tools.
- Investigate system logs, authentication activity, processes, DNS, proxy and email activity.
- Handle escalated security investigations and determine the appropriate response.
- Perform approved incident containment actions such as host isolation and account disablement.
- Support incident response, evidence collection and recovery activities.
- Develop and improve security detection rules using KQL, SPL, ES|QL, EQL or similar tools.
- Identify and reduce false positives through detection tuning.
- Participate in threat hunting and apply threat intelligence to investigations.
- Maintain security runbooks, playbooks and investigation records.
- Track remediation actions and verify that security issues have been resolved.
- Prepare investigation updates and contribute to security reports.
- Work closely with NOC, engineering and client teams during security incidents.
- Participate in the rotating after-hours on-call roster.
- Support continuous improvement, knowledge sharing and client onboarding activities.
Requirements
- 3–5 years of experience in SOC, security operations or MDR environments.
- Experience handling Level 2 or escalated security investigations.
- Hands-on experience with at least one SIEM platform such as Splunk, Microsoft Sentinel, Elastic, QRadar or FortiSIEM.
- Experience with an EDR/XDR platform such as CrowdStrike, SentinelOne, Microsoft Defender or Cortex XDR.
- Working knowledge of KQL, SPL, ES|QL, EQL or similar query languages.
- Familiarity with Sigma and MITRE ATT&CK.
- Good understanding of Windows, Linux, Active Directory and Microsoft 365/Azure security.
- Good knowledge of TCP/IP, DNS, HTTP/TLS, firewalls, proxies and VPNs.
- Experience using ITSM platforms such as ServiceNow or Jira Service Management.
EA Number: 11C4879