





Metro location, general SOC role, and broad toolset requirements increase candidate competition.
Core SOC and incident response skills transfer across industries, so background fit sensitivity is low.
Explicit 1–3 year requirement plus mandatory SIEM/EDR familiarity makes shortlisting moderately strict.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Investigate, respond to, and drive corrective actions for security alerts and incidents, including root cause analysis.
Lead incident response efforts by coordinating with Security, IT, and Business teams to contain and remediate threats.
Continuously improve detection and response processes via automation, runbook development, SOP creation, and integration of threat intelligence.
1–3 years experience in SOC, incident response, IT security operations, or related roles such as EDR admin or blue team intern.
Proficiency with at least one cybersecurity tool/platform such as SIEM, EDR/XDR, secure email gateway, or cloud security tools (e.g. M365 Defender, Sentinel, Splunk, CrowdStrike).
Familiarity with investigation concepts including event correlation, MITRE ATT&CK, malware/TTPs, phishing, and basic networking (TCP/IP, DNS, HTTP, VPN) and Windows/Linux fundamentals.
Strong communication skills to explain technical issues to non-technical users and clear documentation; experience working in a ticket-driven environment with SLAs.
Experienced in handling complex security incidents with operational knowledge of modern cybersecurity tools and incident response workflows.
Analytical and process-focused, capable of improving detection and response mechanisms using automation and playbooks.
Comfortable working cross-functionally under fast-paced, SLA-driven conditions and able to mentor or collaborate effectively with teams.