SpaceBlock Technology
|SOC Analyst
Highlights
Monitor and respond to alerts from endpoint security tools solutions
Review and analyze logs from various sources (e.g., network devices, security, endpoints, applications) to identify potential security incidents.
Examine network traffic patterns and anomalies to identify potential threats
Analyze and respond to brute force attack, phishing attacks by identifying malicious emails, communicating with affected users, and blocking identified threats.
Review and monitor user access controls and permissions to ensure compliance with security policies.
Support the development and delivery of security awareness training programs for employees to improve their understanding of security best practices.
Examination of vulnerabilities in computer systems and networks.
Performing vulnerability assessments using tools like Nessus.
Conducting comprehensive penetration testing to identify network, endpoint, & application vulnerabilities.
Document and communicate security findings and recommendations effectively.
Collaborate with IT teams to ensure timely patching of systems and applications based on identified vulnerabilities and threat intelligence.
Monitor and enforce secure configurations of systems and applications, ensuring compliance with security policies and standards.
Support the implementation and monitoring of a Zero Trust security model within the organization.
Regularly review audit logs for suspicious activities and anomalies that may indicate a security threat
Communicate effectively with non-technical stakeholders, providing clear and concise updates on security incidents and response action.
Proficient in deploying, configuring, and managing Splunk Enterprise environments.
Expertise in creating advanced Splunk searches, reports, and dashboards for data analysis.
Setting up real-time alerts and automation using Splunk for proactive monitoring.
Experience in developing and customizing Splunk apps, add-ons, and modular inputs.
Knowledge of using Splunk for security monitoring, event correlation, and threat detection.
Ability to perform deep-dive data analysis and create insightful visualizations using Splunk.
Experience in deploying and managing Universal Forwarders and Heavy Forwarders for efficient data collection and forwarding.
Experience in integrating Splunk with security and IT operations tools, including apps for PaloAlto, Cisco,Azure,AWS,Microsoft,etc.