Security Analyst
The Cyber Security Defense Center (CDC) is looking for a new profile to join the Operations Team. As a Tier 1 Cyber Defense Center (SOC) Analyst, you will be tasked with the initial detection, triage, and response to security incidents, reporting, and contributing to continuous improvement. You will collaborate with the CDC Engineering Team, internal Nokia teams, external Security Suppliers, and various technology vendors.
This role is for a skilled security professional who will play a critical role in safeguarding Nokia's digital assets through vigilant monitoring and rapid initial response. We are seeking a candidate with a foundational understanding of security principles, and practical experience with security monitoring tools. This individual will be responsible for performing initial security investigations, escalating incidents, and utilizing security tools to maintain a strong security posture.
- Security Monitoring and Triage: Monitor security alerts and events from various security tools and platforms (e.g., SIEM, EDR, Cloud Security tools).
- Initial Incident Response: Perform initial investigation and triage of security incidents, identifying potential threats and determining their scope and impact.
- Incident Escalation: Accurately document and escalate security incidents to Tier 2/3 analysts or other relevant teams following established procedures.
- Tool Utilization: Operate and utilize security tools such as Microsoft Sentinel, Microsoft Defender for Endpoint (MDE), Microsoft Defender for Identity (MDI), and SASE solutions for monitoring and initial response.
- Log Analysis: Conduct basic log analysis to identify suspicious activities and gather evidence related to security events.
- Documentation: Maintain accurate and detailed records of security incidents, investigations, and actions taken.
- Process Improvement: Assist in improving SOC processes and playbooks by providing feedback on incident handling and tool effectiveness.
- Threat Awareness: Stay informed about current security threats, vulnerabilities, and attack techniques.
- Experience: 1-3 years of experience in a Security Operations Center (SOC) or similar security monitoring role.
- Security Fundamentals: Foundational understanding of security principles, common attack vectors, and incident response methodologies.
- Tooling Experience: Practical experience working with security monitoring tools, specifically with one or more of the following systems:
- Microsoft Sentinel
- Microsoft Defender for Endpoint (MDE)
- Microsoft Defender for Identity (MDI)
- Wazuh (EDR)
- SASE solutions
- Analytical Skills: Ability to analyze security alerts, identify patterns, and perform initial problem-solving.
- Communication Skills: Ability to communicate technical information clearly and concisely, both verbally and in writing.
- Basic Cloud Security: Basic understanding of cloud security principles and common cloud security threats.
- OS Internals: Basic knowledge of OS internals (Windows/Linux/macOS) and network fundamentals.
ย
Recommended Certifications (considered a plus):
- CompTIA Security+
- Microsoft SC-200 (Security Operations Analyst Associate)
- Certified SOC Analyst (CSA) โ EC-Council