SOC Analyst L1
Opportunity Information
PPS-7
2
Federal Government Attached Department/ Project
Mid Career
Contract
The Role
The SOC Analyst L1 continuously monitors security alerts and logs via SIEM platforms, triages alerts and escalates confirmed incidents at the National Telecommunication and Information Security Board (NTISB). Two contract positions are available.
• Continuous monitoring of security alerts and logs via SIEM platforms to identify potential threats in real-time • Performing initial alert triage to distinguish between genuine security incidents and false positives • Documenting all findings and creating incident tickets within a tracking system for audit and compliance • Reviewing user-reported phishing emails by analyzing headers, links, and attachments for malicious intent • Executing basic remediation steps such as resetting compromised user passwords or isolating endpoints • Collecting preliminary evidence and data enrichment (IP reputation, domain history) for every validated alert • Escalating confirmed or complex security incidents to Tier 2 analysts with a detailed summary • Monitoring the health and status of security sensors to ensure logs are feeding into the SIEM correctly • Running and reviewing scheduled vulnerability scans to identify unpatched systems or misconfigurations • Maintaining shift handover reports to ensure continuity in monitoring and pending incident status
Applicants General Eligibility & Requirements
• Five years' general age relaxation has already been added to the upper age limit; no other age rel
4+ years
26 to 35 years
Education, Experience and Skills Requirements
- Bachelor 16 Years: Cyber Security, Computer Science, Information Technology, Computer Engineering, Software Engineering
- MS / MPhil: Cyber Security, Computer Science
- Masters: Computer Science
• Minimum 4 years of experience, of which 2 years of recent experience as a SOC analyst
SIEM Tools, Alert Triage, Incident Response, Phishing Analysis, Vulnerability Scanning
• Certifications on Incident Handling, SOC operations or offensive certifications (preferable)
National Telecommunication and Information Security Board (NTISB)