Posted on: 12/01/2026
Role Overview :
The SecOps Specialist is responsible for monitoring, analyzing, and responding to security events escalated from L1 analysts. This role provides advanced operational support, ensures timely incident resolution, and contributes to the continuous improvement of enterprise security operations.
Key Responsibilities :
- Investigate alerts escalated from L1 analysts using SIEM, EDR, and threat intelligence platforms.
- Perform deeper log analysis, correlation, and triage to validate true positives vs. false positives.
- Escalate confirmed incidents to L3 or Incident Response teams with detailed context.
Incident Response Support :
- Contain and remediate security incidents under guidance from L3/SOC leads.
- Document incident timelines, actions taken, and lessons learned.
- Assist in forensic investigations and evidence collection.
Threat & Vulnerability Management :
- Support vulnerability scanning and patch validation activities.
- Track remediation progress and report on outstanding risks.
- Provide input into threat intelligence feeds and detection rules.
Tool Administration & Optimization :
- Operate and tune security tools (SIEM, IDS/IPS, EDR, DLP, firewalls).
- Suggest improvements to detection rules, dashboards, and workflows.
- Maintain playbooks and SOPs for common incident types.
Collaboration & Reporting :
- Work closely with L1 analysts, L3 specialists, and SOC managers.
- Provide detailed incident reports and metrics to leadership.
- Contribute to knowledge base articles and training materials.
Required Skills & Experience :
- Strong knowledge of SIEM platforms (Splunk, QRadar, Sentinel), EDR tools, and IDS/IPS.
- Familiarity with ITIL processes and incident management workflows.
- Good understanding of common attack vectors, malware, phishing, and network security.
- Strong analytical, documentation, and communication skills.
Preferred Qualifications :
- Experience with scripting/automation (Python, PowerShell) for SOC workflows.
- Exposure to cloud security monitoring (Azure, AWS, GCP).
- ITIL v4 certification.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1600047