SOC L1 Cyber Security Analyst
Doha, Doha Municipality, Qatar · Full Time
Be the first to apply
- Experience
- 1–3 yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- In office
- Education
- Bachelor's degree
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Overview
The Level 1 (L1) Cyber Security Analyst acts as the primary defense within a 24/7 Security Operations Center (SOC), responsible for real-time surveillance, examination, and triage of security alerts to detect and address cyber threats. This role is instrumental in incident handling and initial security service management, ensuring clients' digital environments remain secure.
Key Responsibilities
- Maintain constant surveillance of security alerts and events sourced from tools such as SIEM, EDR, IDS/IPS, and others.
- Examine and prioritize security alerts, distinguishing false alarms from genuine threats by performing preliminary investigations and log reviews.
- Assign categories and urgency levels to security incidents following predefined guidelines.
- Act as the initial responder to security incidents, following established playbooks to initiate incident response procedures.
- Conduct early containment efforts including system isolation to curb threat propagation.
- Collect and safeguard forensic data and logs for detailed investigation by senior analysts.
- Document incidents thoroughly with accurate summaries of findings and actions taken, escalating complex cases to Level 2 analysts or senior teams.
- Oversee health and functionality of security infrastructure like firewalls, SIEM, and EDR agents; perform basic troubleshooting and escalate issues as needed.
- Assist in refining security monitoring rules and alerts under supervision to enhance detection capabilities.
- Fully manage security services for clients, including monitoring and protection against DDoS attacks, software updates, patching, health checks, preventive maintenance, and return merchandise authorizations (RMAs).
- Operate on a rotational 24/7 shift schedule including nights, weekends, and holidays to maintain continuous security operability.
- Ensure smooth transition during shift changes by delivering comprehensive handovers.
- Collaborate closely with peers and other IT/security departments for a unified response to security incidents.
Required Qualifications and Skills
- Bachelor’s degree in Cybersecurity, Computer Science, IT, or equivalent professional experience.
- Preferably 1-3 years working in a SOC or related cybersecurity role, ideally within a Managed Security Service Provider (MSSP) setting.
- Certifications such as CompTIA Security+, Certified SOC Analyst (CSA), or GIAC Security Essentials (GSEC) are favored.
- Solid foundational knowledge of cybersecurity principles, networking protocols including TCP/IP, and operating systems like Windows and Linux.
- Experience with SIEM solutions such as Splunk, QRadar, Microsoft Sentinel, or LogRhythm for log analysis and monitoring.
- Understanding of incident response workflows and best practices.
- Strong analytical thinking and problem-solving capabilities.
- Effective written and oral communication skills essential for thorough incident documentation and reporting.
- Meticulous attention to detail with ability to sustain focus during repetitive monitoring tasks.
- Capability to perform efficiently under pressure in a fast-paced, round-the-clock operational environment.
Minimum education
Bachelor's Degree
Skills
How they work
Communication
Problem Solving
Attention to Detail
Stress Management