L3 Senior Security Analyst (DSC/JH)
ST ENGINEERING INFO-SECURITY PTE. LTD.
Job Summary
The Tier 3 Senior SOC Analyst acts as the Deputy SOC Manager and provides leadership for SOC operations. The role includes threat hunting, incident analysis, process optimization, unveil presentation, and team mentorship, ensuring the highest level of security operations for MSSP clients.
Responsibilities
Leadership and Oversight
- Serve as the Deputy SOC Manager and lead Tier 1 and Tier 2 analysts by example.
- Conduct training sessions, provide coaching, and ensure continuous skill development for the team.
- Plan relevant certifications for Tier 1 and Tier 2 analysts, ensuring proper progression with certifications arranged yearly.
Threat Hunting and Incident Analysis
- Actively hunt for threats, identify unknown vulnerabilities, and close security gaps within networks.
- Identify all security attack vectors, classify incidents, and assess their impact.
- Review all escalations from Tier 1 and Tier 2 analysts, ensuring comprehensive analysis and daily updates to the SOC Manager;
- Proactively update documentation, processes, workflows, and other operational aspects for continuous improvement.
Threat Detection
· MITRE ATT&CK techniques
· Threat intelligence reports
· Security incident trends
· Business-specific risks
- Create and optimize SIEM detection rules
- Validate detection effectiveness through testing and simulation exercises
False Positive Management
- Work closely with Tier 2 analysts to gather feedback and evidence on false positives.
- Finetune use cases to reduce false positives across all customers.
- Ensure consistent application of false positive reduction measures for all MSSP clients.
Operational Excellence
- Maintain oversight of SOC processes to ensure compliance and operational effectiveness.
- Plan and implement improvements to SOC operations, focusing on proactive threat detection and response.
- Monitor and "police" SOC workflows, providing tracking and daily updates to SOC leadership.
Technology Refresh
- Contribute to the testing of new technology (such as AI)
- Review and compare against current technology to improve SOC operations
Requirements
- Extensive experience in SOC operations, including threat hunting and advanced incident analysis.
- Strong understanding of SIEMs, threat intelligence platforms, and security tools.
- Leadership experience with a track record of mentoring and developing security teams.
- Relevant certifications (e.g., CISSP, CISM, GCIH) are highly preferred.
- Excellent communication, documentation, and organizational skills.
- Ability to handle high-pressure situations and critical security incidents effectively.
- A collaborative mindset to work effectively with other SOC tiers and managers.
- Strong analytical and problem-solving skills to address complex security challenges.
- Commitment to continuous learning to stay updated with the latest security trends and technologies.
- Adherence to SOC playbooks, standard operating procedures, and compliance requirements.
- Willingness to work in a dynamic 24/7 SOC environment.
Location: Ang Mo Kio.