Apply Edge Start your job search

SOC Analyst

Spait Infotech · Canada

Apply & track with Apply Edge
Key ResponsibilitiesMonitor security alerts and events from SIEM, EDR/XDR, firewall, IDS/IPS, antivirus, email security, and other security tools.Perform real-time monitoring of security events in a 24×7 SOC environment.Investigate and triage security alerts based on severity, priority, and potential business impact.Identify false positives and distinguish them from genuine security incidents.Perform initial investigation and incident analysis using logs, alerts, endpoint data, and network activity.Analyze Indicators of Compromise (IOCs) such as IP addresses, domains, URLs, file hashes, and suspicious processes.Investigate common threats including:Phishing and malicious emailsMalware and ransomwareBrute-force attacksUnauthorized accessAccount compromiseSuspicious PowerShell activityData exfiltrationNetwork intrusionEscalate confirmed or complex incidents to L2/L3 analysts, Incident Response, or Security Engineering teams.Create and maintain detailed incident tickets and investigation documentation.Perform basic threat hunting and identify suspicious patterns across security data.Correlate events across multiple security platforms to identify attack activity.Follow defined SOPs, playbooks, escalation procedures, and SLAs.Participate in incident response activities, including containment and remediation support.Support vulnerability management and security monitoring activities when required.Track emerging threats, vulnerabilities, malware campaigns, and attack techniques.Contribute to improving detection rules, SIEM use cases, and SOC processes.Prepare daily, weekly, and monthly security monitoring reports.Required Technical SkillsGood understanding of Cybersecurity fundamentals.Strong knowledge of networking concepts:TCP/IPDNSHTTP/HTTPSVPNFirewallsProxiesNetwork protocolsHands-on experience with SIEM tools, such as:Microsoft SentinelSplunkIBM QRadarLogRhythmElastic SecurityKnowledge of endpoint security/EDR tools such as Microsoft Defender, CrowdStrike, or SentinelOne.Understanding of Windows and Linux security logs.Knowledge of authentication technologies such as Active Directory, Azure AD/Entra ID, MFA, and SSO.Ability to perform log analysis and event correlation.Understanding of malware, phishing, vulnerability, and common attack techniques.Familiarity with MITRE ATT&CK, IOC analysis, and threat intelligence.Basic knowledge of incident response and digital forensics.Familiarity with security frameworks such as NIST, ISO 27001, or CIS Controls is an advantage.SIEM / Query SkillsCandidates should have experience with or willingness to learn SIEM query languages, such as:KQL – Microsoft Sentinel / DefenderSPL – SplunkAQL – IBM QRadarElasticsearch Query / KQL – Elastic Security