Integrity360 logo
Integrity360Posted 1 month ago

L2 SOC Analyst

On-siteParis, Île-de-France, France

Full TimeMedium

Job Summary

Analyze security alerts and incidents, following defined investigation processes to determine risk and impact on customers. Perform ad-hoc analysis of varied logs to identify anomalies in customer environments, including industrial network traffic or asset behavior. Conduct in-depth investigations on confirmed security incidents, assisting senior analysts to mitigate threats and identify threats from cyber criminals, ATPs, and Nation States. Identify and document tuning opportunities, perform enriching queries, and assist in report creation for core stakeholders. Monitor alerts related to Operational Technology (OT) environments, support investigations involving industrial systems, and escalate complex OT-related cases to Level 3 analysts as required.

Required Qualifications

  • Experience working with security event detection tools like IPS, SIEM, DLP, Anti-virus, etc.
  • Ability to perform event correlation, host/ network threat analysis
  • Ability to manage multiple incidents and make effective decisions under high pressure environment
  • Experience in performing analysis on network pcaps and documents for malicious activity or codes
  • Conceptual knowledge in Networks and Network Security
  • Understanding of Network infrastructure hardware and protocols (TCP/IP, switches, bridges, routers, proxy servers, VPN concentrators)
  • Understanding of Security protocols (IPSec), and encryption technologies (3DES, AES, SHA2, TLS)
  • Understanding of basic security principles such as Confidentiality, Availability, Integrity
  • Familiar with security best practices
  • Strong Microsoft Word & Microsoft Excel skills required
  • Basic understanding or strong interest in Operational Technology (OT) environments
  • Awareness of industrial systems such as SCADA, DCS, PLCs and HMIs
  • Experience working with security event detection tools like IPS, SIEM, DLP, Anti-virus, etc.
  • Experience using SIEM & IPS solutions
  • Strong Microsoft Word & Microsoft Excel skills required
  • Basic understanding or strong interest in Operational Technology (OT) environments
  • Awareness of industrial systems such as SCADA, DCS, PLCs and HMIs
  • Security industry certifications: SEC+, CYSA+, Net+, SC-200,AZ-500,AZ-900,Splunk Power user
  • A working knowledge of Intrusion Prevention System (IPS), SIEM, SOAR & DLP
  • Experience working with threat hunting tools

Desired Qualifications

  • Experience with Splunk is a plus
  • Experience using SIEM & IPS solutions is a plus
  • A process of on-going certification for the benefit of the business and for self-development is encouraged
  • Review the adequacy of the security controls and their ability to protect the information system and its information
  • Experience with Splunk is a plus
  • Experience using SIEM & IPS solutions is a plus
  • A process of on-going certification for the benefit of the business and for self-development is encouraged
  • Review the adequacy of the security controls and their ability to protect the information system and its information
  • Experience working with threat hunting tools is nice to have
  • Interest in pursuing OT-related training or certifications is encouraged
  • Exposure to industrial protocols or networks is a plus
  • Willingness to learn and develop skills in OT security monitoring

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce