- Company Name
- Cantor Fitzgerald
- Job Title
- Security Operations Center Analyst
- Job Description
-
Job Title: Security Operations Center Analyst
Role Summary:
Act as a frontline defender in a global SOC, continuously monitoring, detecting, and responding to security threats across Linux, Windows, and cloud environments (AWS, Azure). Design, implement, and refine detection logic, playbooks, and automation to enhance incident response. Collaborate with infrastructure, application, and compliance teams to enforce secure configurations and maintain robust security posture.
Expectations:
- Deliver 24/7 vigilance over enterprise security events with minimal false positives.
- Lead investigations, develop actionable incident reports, and conduct post‑incident reviews.
- Drive process improvement and automation to reduce mean time to detect (MTTD) and mean time to respond (MTTR).
- Maintain up‑to‑date knowledge of emerging threats, vulnerabilities, and security technologies.
Key Responsibilities:
• Monitor SIEM (Splunk, Azure Sentinel) dashboards and respond to alerts in real time.
• Create and maintain detection rules, KQL/SPL queries, custom parsers, and SOAR playbooks.
• Perform threat hunting, forensic analysis, and packet capture analysis (Wireshark, TCPDump).
• Collaborate with infra/app teams to secure configurations, manage certificate lifecycle, and enforce IAM policies in AWS/Azure.
• Administer and tune endpoint protection (Microsoft Defender, EDR), IDS/IPS, and vulnerability management tools.
• Document incident response procedures, update network/asset diagrams, and provide post‑incident summaries.
• Communicate findings and recommendations to cross‑functional teams and third‑party vendors.
Required Skills:
- Linux & Windows OS administration (≥3 yrs).
- SIEM/SOAR: Splunk, Azure Sentinel, Cribl.
- EDR & threat detection (Microsoft Defender, Palo Alto Cortex).
- Cloud administration: AWS, Azure (IAM, IaaS, PaaS).
- KQL (Sentinel) & SPL (Splunk) query writing.
- Scripting: PowerShell, Python (basic).
- Ticket & project management: ServiceNow, Dynamics 365, Jira, Smartsheet.
- DNS, certificate management (Digicert, AppViewX).
- Networking fundamentals, packet analysis.
- Strong written and verbal communication, teamwork across global functions.
Required Education & Certifications:
- Bachelor’s Degree in MIS, CIS, Cybersecurity, or related field.
- Minimum 5 yrs of SOC experience, 3 yrs Linux admin, 2 yrs cloud admin.
- Mandatory: CISSP, CISM, or comparable security certification.
- Preferred: AWS Security Specialty, CISA, GIAC, Security+ (optional).
---