The Senior SOC Analyst is responsible for advanced security monitoring, incident investigation, threat hunting, detection engineering, incident response, and security automation.
The role requires strong hands-on experience in investigating complex cybersecurity incidents, identifying attacker behaviors and TTPs, developing and tuning security detections, and designing automated SOC workflows using SOAR platforms.
The analyst is expected to continuously improve SOC detection and response capabilities by identifying detection gaps, reducing false positives, improving investigation processes, and automating repetitive security operations.
Key Responsibilities
- Perform advanced investigation and analysis, containment, eradication, recovery, root cause analysis, and post-incident review.
- Conduct proactive threat hunting using SIEM, EDR/XDR, network, authentication, and application telemetry.
- Map security incidents and detection scenarios to the MITRE ATT&CK framework.
- Develop, implement, test, and tune SIEM correlation and detection rules.
- Reduce false positives and continuously improve detection accuracy and coverage.
- Develop and maintain SOC playbooks, runbooks, investigation procedures, and incident response procedures.
- Support digital forensic and malware analysis activities when required.
- Coordinate with infrastructure, network, endpoint, application, DevOps, and security engineering teams during security incidents.
- Analyze incident trends and contribute to SOC metrics, reports, lessons learned, and continuous improvement initiatives.
- Design, develop, implement, and maintain SOAR workflows and automated incident response playbooks.
Technical Skills
- Strong hands-on experience with SIEM and detection engineering, preferably Splunk Enterprise Security, including SPL, correlation rules, data models, and Risk-Based Alerting (RBA).
- Experience with SOAR and security automation, including playbook development, REST APIs, JSON, webhooks, and security-system integrations.
- Strong knowledge of incident response, threat hunting, advanced log analysis, event correlation, and MITRE ATT&CK/TTP analysis.
- Strong understanding of Windows, Linux, Active Directory, identity security, and network protocols, including TCP/IP, DNS, HTTP/HTTPS, TLS, VPN, firewalls, and proxies.
- Knowledge of web application attacks and OWASP techniques, as well as malware behavior, persistence, privilege escalation, credential access, lateral movement, defense evasion, and command-and-control techniques.
- Experience with digital forensics, malware analysis, IOC investigation, and Threat Intelligence platforms such as MISP.
- Experience with network security analysis tools such as Zeek, Suricata, Snort, and Wireshark.
Experience & Qualifications
- 5+ years of cybersecurity experience, with strong hands-on experience in SOC operations, incident response, threat hunting, detection engineering, or security automation.
- Demonstrated experience investigating complex cybersecurity incidents.
- Practical experience developing and tuning SIEM detection and correlation rules.
- Practical experience designing or implementing SOAR workflows and security automation.
- Strong understanding of enterprise network, endpoint, identity, application, and security architectures.
- Ability to independently investigate incidents from initial detection through containment, root cause analysis, and lessons learned.
- Ability to translate attacker behaviors and investigation findings into new detections, hunting scenarios, and automation workflows.
- Strong technical documentation, analytical, problem-solving, and communication skills.
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field is preferred; equivalent practical experience is also acceptable.
توسعه فناوری گروه فارابی از سال ۱۳۹۲ با یک هدف روشن پا به عرصه گذاشت: ساختن بستری که بتواند مسیرهای مالی و سرمایهگذاری را برای همه آسانتر کند.
در این سالها، همیشه به دنبال نوآوری و ارائه راهکارهایی بودیم که کاربران را یک قدم به آیندهای مطمئنتر نزدیک کند. از پلتفرم فارابیکسو که معاملات بورس را روانتر میکند، تا فارابیزون که سرمایهگذاری را سادهتر و کارآمدتر میسازد. جیبیمو هم راهی سریع و ایمن برای پرداختهای الکترونیکی فراهم کرده، و پینوست به عنوان یک دستیار مالی هوشمند، کاربران را در تصمیمات مالی همراهی میکند.
ما در توسعه فناوری گروه فارابی باور داریم که فناوری میتواند تحولی بزرگ در دنیای مالی ایجاد کند، و هر روز تلاش میکنیم تا ابزارهایی بسازیم که زندگی مالی شما را راحتتر و هوشمندتر کند.