Soc Security Analyst positions focus on delivering results in their domain. This page aggregates open Soc Security Analyst roles and what employers typically expect.
About Gruve Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks. About the role We are seeking a highly skilled Security Analyst to join our Security Operations Center (SOC) team. The ideal candidate should have a strong foundation in SIEM monitoring & XDR or EDR solutions, and security analysis, with hands-on experience in investigating and responding to security alerts. This role requires expertise in reviewing and analyzing L1 alerts, providing detailed recommendations, and engaging with customers for incident handling. The candidate should also have a basic SIEM administration background and Python scripting skills for troubleshooting and playbook development. Key Roles & Responsibilities: Incident Detection and Response Analyze and Respond to Security Alerts: Review and investigate security alerts escalated from L1 analysts or generated by security monitoring tools (SIEM, IDS/IPS, EDR). Incident Triage: Conduct initial analysis of potential security incidents to determine severity, impact, and scope, including identifying false positives. Incident Escalation: If necessary, escalate incidents to L3 SOC analysts for deeper investigation and remediation. Containment: Take appropriate containment actions to limit the impact of ongoing security incidents (e.g., isolating affected systems, blocking malicious IP addresses). Incident Documentation: Accurately document and report security incidents in a clear and comprehensive manner for later analysis and compliance requirements. Threat Hunting and Monitoring Proactive Threat Hunting: Identify potential threats and vulnerabilities by analyzing logs, network traffic, and other security data to find hidden threats or weaknesses. Monitor Security Systems: Regularly monitor and assess security infrastructure, including firewalls, intrusion detection systems, and endpoint protection tools, to detect anomalies and potential attacks. Alert Tuning: Adjust and refine alerts within security tools (SIEM, XDR) to improve detection and reduce false positives. Security Tool Management Security Systems and Tools Management: Assist in the configuration, management, and maintenance of security tools (e.g., SIEM & XDR tools) to ensure effective threat detection. Log Review: Review logs from various sources such as network devices, servers, and applications to identify security events or irregular activities. SIEM & XDR Management: Ensure SIEM & XDR tools are operating properly, fine-tune them for better accuracy, and perform searches on security data. Collaboration and Escalation Work with L1 Analysts: Provide guidance and mentorship to L1 analysts on how to identify and escalate security incidents appropriately. Collaborate with Other Teams: Coordinate with internal teams (network security, IT operations, application security, etc.) to address vulnerabilities, incidents, and other security concerns. Incident Escalation to L3: For complex or advanced incidents, escalate issues to L3 analysts for deeper investigation and remediation. Customer Communication & Incident Handling Engage with customers during security incidents and provide expert guidance. Conduct technical discussions to explain security threats and mitigation steps. Collaborate with internal and external teams for incident resolution. Playbook Management & Troubleshooting Understand and modify XDR playbooks to automate security operations. Troubleshoot playbook errors and optimize automation workflows. Identify gaps in existing security automation and recommend enhancements Security Reporting and Documentatio…