Job Description & How to Apply Below
SOC Administrator / Senior SOC Analyst
We are looking for an experienced SOC Administrator / Senior SOC Analyst with strong hands‑on experience in Arc Sight SIEM administration, SOC operations, incident investigation, SIEM engineering, threat hunting, and security solutioning.
The candidate will be deployed onsite at a customer location and will act as a senior technical security resource responsible for managing SIEM operations, supporting L1/L2 analysts, handling advanced investigations, maintaining security tools, improving detection use cases, and advising the customer on security operations decisions.
Key Responsibilities SOC Administration & SIEM Management- Administer and manage Arc Sight ESM, Arc Sight Logger, Elastic Search, Smart Connectors, content packs, rules, dashboards, reports, active channels, filters, and correlation use cases.
- Monitor SIEM platform health, connector status, event flow, EPS utilization, storage, parsing quality, and log source availability.
- Troubleshoot log ingestion issues, connector failures, parsing errors, event normalization issues, and correlation rule performance problems.
- Perform SIEM tuning to reduce false positives and improve detection accuracy.
- Develop and maintain SIEM content including correlation rules, dashboards, reports, threat use cases, and alert workflows.
- Support onboarding of new log sources including network devices, servers, cloud platforms, EDR, AV, IAM, and application logs.
- Maintain documentation for SIEM architecture, log source inventory, use cases, SOPs, escalation matrix, and operational runbooks.
- Perform deep‑drive analysis of security alerts, suspicious activities, malware detections, endpoint events, cloud events, and network anomalies.
- Lead incident triage, validation, containment recommendations, root cause analysis, and post‑incident reporting.
- Review and improve SOC investigation workflows, alert handling procedures, and escalation processes.
- Perform threat hunting across SIEM, EDR, endpoint, cloud, firewall, proxy, DNS, identity, and email security logs.
- Support customer security teams during major incidents, audit queries, and security improvement initiatives.
- Design, develop, and enhance security monitoring use cases aligned with MITRE ATT&CK, current threat trends, and customer risk priorities.
- Translate business and technical risks into actionable SIEM detection logic.
- Create and tune detection rules for endpoint threats, privilege abuse, lateral movement, brute force, suspicious cloud activity, data exfiltration, malware, ransomware, and insider threats.
- Validate rule logic, reduce noisy alerts, and improve SOC investigation quality.
- Support integration of SIEM with ticketing tools, SOAR platforms, automation scripts, threat intelligence feeds, and customer security tools.
- Work with and support technologies such as EDR/XDR platforms, antivirus / endpoint protection solutions, Linux and Windows security logging, Azure security services, AWS security services, cloud logs, and threat intelligence platforms.
- Assist in security solutioning, tool integration, and operational improvement discussions with the customer.
- Identify gaps in monitoring, visibility, detection coverage, and response processes.
- Work onsite with the customer’s security and IT teams on daily SOC operations.
- Provide clear technical guidance and help the customer make informed security decisions.
- Prepare daily, weekly, and monthly SOC reports, incident summaries, health checks, and improvement recommendations.
- Communicate professionally with customer stakeholders, SOC teams, and management.
- Take ownership of issues and follow through until resolution.
- Maintain a calm, confident, soft‑spoken, and collaborative working style.
- 5–8+ years of cybersecurity experience with strong exposure to SOC operations and SIEM administration.
- Hands‑on experience with SIEM, preferably Arc Sight ESM, Logger, Smart Connectors, correlation rules, dashboards, reports, and connector management.
- Prior experience working in a combined SOC Admin…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×