Deskripsi Pekerjaan
Are you passionate about cybersecurity and looking to make a tangible impact? KMC Solutions is seeking a skilled and proactive SOC Analyst (Microsoft Sentinel) to join our dynamic team. In this hybrid role, you will play a crucial part in protecting our organization's digital assets from sophisticated cyber threats.
We utilize advanced technologies, specifically Microsoft Sentinel, to monitor, detect, and respond to security incidents in real-time. You will collaborate with cross-functional teams to investigate alerts, analyze logs, and implement robust security measures to stop attacks before they cause damage. This is an exciting opportunity to grow your career in a leading semiconductor environment.
Tanggung Jawab
- Monitor Security Events: Continuously track security alerts and events using Microsoft Sentinel to ensure 24/7 visibility across the network.
- Incident Investigation: Triage, investigate, and analyze security incidents to determine scope, impact, and root cause.
- Threat Analysis: Analyze logs, telemetry data, and indicators of compromise (IOCs) to identify malicious activities and anomalies.
- Incident Response: Collaborate with incident response teams to remediate threats, isolate affected systems, and restore system integrity.
- Playbook Development: Contribute to the development, testing, and maintenance of security playbooks and runbooks.
- Vulnerability Management: Perform regular vulnerability assessments and support internal security audits.
- Reporting: Document findings accurately and maintain detailed incident reports for management review.
Kualifikasi
- Education: Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related field.
- Experience: Proven experience working as a SOC Analyst or within a Security Operations Center (SOC).
- Tech Stack: Strong knowledge and hands-on experience with Microsoft Sentinel, Log Analytics, and Kusto Query Language (KQL).
- General Security: Familiarity with SIEM platforms, threat intelligence, and standard incident response procedures.
- Networking: Solid understanding of networking concepts, including TCP/IP, firewalls, VPNs, and switches.
- Certifications: Relevant security certifications such as CISSP, CEH, Security+, or CompTIA Security+ are highly preferred.
- Skills: Excellent analytical thinking, problem-solving abilities, and communication skills.