hackquest logo

Soc Analyst L1

D

Dynamicminds Business Solutions, Inc

20 - 25K PHP
Full-time
N/A
Networking FundamentalsSIEM MonitoringLog AnalysisThreat AwarenessMITRE ATT&CKTriage & EscalationComputer LiterateTechnical Skills

The SOC Analyst (Level 1) is the front line of our Security Operations Center. In this role you will monitor security alerts around the clock, triage potential threats, and escalate confirmed incidents with speed and precision. You will work alongside senior analysts and incident responders, applying established playbooks to separate genuine threats from noise and ensuring that nothing slips through the cracks. It is an ideal entry point for someone building a career in cybersecurity who wants hands-on exposure to real-world detection and response.


Key Responsibilities

  • Monitor SIEM dashboards and security alerts across the environment, identifying anomalies and potential indicators of compromise.
  • Perform first-level triage of alerts — validating, prioritising, and classifying events to distinguish true threats from false positives.
  • Investigate suspicious activity using Windows Event and Linux logs, correlating data across sources to establish scope and impact.
  • Escalate confirmed or high-priority incidents to Tier 2 analysts and incident responders following established playbooks, with clear and complete handover notes.
  • Recognise common attack patterns — phishing, malware, and brute-force attempts — and respond according to standard operating procedures.
  • Map observed activity to the MITRE ATT&CK framework to support consistent threat classification and reporting.
  • Document all alerts, investigations, and actionstaken to maintain an accurate audit trail and support continuous improvement ofdetection rules.
  • Contribute to shift handovers and ongoing monitoring coverage of the Security Operations Center.


What You Bring

  • Networking fundamentals — a solid grasp of TCP/IP, DNS, and common ports & protocols.
  • Log analysis — the ability to read and interpret Windows Event and Linux logs.
  • SIEM monitoring — familiarity with one or more platforms such as Splunk, Microsoft Sentinel, or QRadar.
  • Threat awareness — working knowledge of phishing, malware, and brute-force attack

techniques.

  • Triage & escalation — comfort following playbooks and producing clear, complete handovers.
  • MITRE ATT&CK — familiarity with the framework and how it is applied to threat

classification.


Certifications

Security+, Network+, or CySA+ certifications are a strong plus but are not required. We welcome candidates who are actively working toward these credentials.