As a member of the Assystem SOC team, you will join an international and senior team in a very demanding unit. You will be expected to learn quickly and multi-task.
After the first training session, you will work with a senior SOC incident manager and your main tasks will be:
- Analysis and interpretation of alerts
- Analysis and qualification of alerts from the SIEM
- Analysis of network flows from the SIEM
- Implementation of correlation rules for detection
- Management of security incidents
- Participation in incident response with experienced analysts
- Monitoring
- Monitoring of threats and attack techniques (TTPs)
- Technology watch on SIEM, EDR, as well as tools related to intrusion detection (Sysmon, EDR, Sandbox, Threat Intel ...),
- Participation in internal workshops (RETEXs, demonstrations, benchmarks, tests ..)
- Reporting and documentation
- Participation in the drafting of activity monitoring reports for customers
Animation of customer operational committees with experienced analysts