Cybersecurity Incident Analyst (Level 1)
Role Summary
The Cybersecurity Incident Analyst (Level 1) is responsible for monitoring, triaging, and supporting the investigation of security incidents within the Security Operations Center (SOC). This role focuses on first-level incident response activities, ensuring timely detection, analysis, and escalation of threats to minimize organizational impact.
The position acts as the first line of defense, identifying suspicious activity, validating incidents, and supporting response efforts to maintain the security and resilience of the enterprise environment.
Key Responsibilities
- Participate in SOC operations, including continuous monitoring, alert triage, and incident handling
- Perform initial analysis and investigation of security events to determine legitimacy and severity
- Escalate confirmed or high-risk incidents to higher-level analysts or incident response teams
- Support incident response activities, including containment actions and coordination with relevant teams
- Execute and maintain daily security monitoring processes, ensuring operational effectiveness and continuous improvement
- Assist in identifying security gaps, vulnerabilities, and control deficiencies across infrastructure and systems
- Support the development and improvement of incident response procedures and playbooks
- Assist in the implementation of enterprise security controls and cybersecurity initiatives
- Recommend security improvements and enhancements to senior staff and management
- Maintain accurate and complete documentation of incidents, including findings, actions, and lessons learned
Experience, Education & Certifications
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field
or - Minimum of 2+ years of experience in cybersecurity operations or incident monitoring.
- Hands-on experience with SIEM solutions and security monitoring tools
- Understanding of IT infrastructure, networks, and security technologies
Exposure to security incident handling, SOC workflows, or breach management (L1/L2 support)
High level of English written and speaking