- Company Name
- Gen
- Job Title
- Principal Security Information Analyst
- Job Description
-
**Job Title**
Principal Information Security Analyst
**Role Summary**
Senior SOC specialist responsible for enhancing detection, monitoring, and incident response capabilities. Leads automation and detection engineering, mentors Tier 1 analysts, and collaborates across security and IT teams to improve security visibility and SOC performance in a 24/7 global coverage environment.
**Expactations**
- Operate within a follow‑the‑sun model, covering on‑call hours for weekends.
- Maintain high alert accuracy, reduce false positives, and sustain up‑to‑date detection documentation.
- Communicate findings and recommendations in clear, concise English to stakeholders.
**Key Responsibilities**
- Monitor, analyze, and correlate security alerts across SIEM, WAF, EDR, cloud, network, and threat intelligence platforms.
- Develop, tune, and validate detection rules, correlation searches, security policies, and dashboards.
- Mentor and support Tier 1 analysts in alert triage and escalation.
- Collaborate with security engineers on automation, enrichment, and workflow optimizations.
- Document detection use cases, workflows, and process improvements.
- Participate in security projects with Incident Response, Security Engineering, Application Security, and IT teams.
- Support incident response playbook execution.
**Required Skills**
- 3–5 years of SOC or detection engineering experience.
- Strong knowledge of networking (TCP/IP, DNS, HTTP/S) and common cyber attack techniques.
- Hands‑on experience with SIEM (Splunk preferred) and rule development.
- Familiarity with WAF technologies and cloud security monitoring (AWS, Azure, GCP).
- Scripting/automation proficiency (Python, PowerShell, API integrations).
- Ability to utilize AI‑based tools for SOC operations.
- Analytical, problem‑solving, and attention‑to‑detail skills.
- Excellent written and verbal English communication.
- Team collaboration across security disciplines.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Relevant certifications (e.g., Splunk Core Certified User/Administrator, AWS/Azure Security Professional, CISSP, CEH) are advantageous.