SOC Analyst L2
1 semana atrás
Company Description
Founded in 2015, **BPCE Infogérance & Technologies** is a subsidiary of Groupe BPCE, dedicated to **Infrastructures**, **End-User Environment**, **Security** and **Production**. Driven by **growth**, **expertise**, **transformation** and **agility**, this project embraces an international mindset and a diverse skill set. You’ll find yourself in a **dynamic and enriching workplace** or, as we like to name it, a real **tech playground**, where you’ll be able to explore a huge tech stack..
**Job Description**:
**We are looking for a SOC Analyst L2 (local contract) to join our BPCE IT business Unit.**
Integrated within the Security Operation Center (SOC) BPCE-IT, the Blue Team is the first line of defence, responsible for defending the enterprise's use of information systems by maintaining its security posture against attackers.
The main activities are the ones below:
- Vulnerability management on critical vulnerabilities (handling, categorization and follow-up)
- Leading incident response plans
- Follow-up of remediation plans
- Implementation of detection scenarios and treatment of associated alerts
The L2 SOC Analyst is responsible for monitoring and analyzing the organization’s networks and systems on a daily basis to detect, identify, investigate, and mitigate potential threats. They must be able to identify anomalous behavior, recognize patterns of malicious activity, and take appropriate corrective action.
In addition to their daily duties, the L2 SOC Analyst will provide recommendations for improving security posture and assist with incident response plans, policies, and procedures. Some additional responsibilities may include recommending tools or solutions, participating in audit activities, providing reporting on security events/incidents and collaborating with other teams across the organization.
**Main Tasks and Responsabilities**:
1) Analysis:
- Participation in improving correlation and log analysis rules
- Conduct investigations and research including statistics
- Interpret or perform first level (Sandbox or manual) minimum scans on malicious codes
- Improve our Threat Intelligence activity
2) Handling incidents:
- Creating, and managing service requests via our ticketing tools (ServiceSnow / SecOps / TheHive)
- Qualify and analyze these elements to determine the cause of the incident, the mode of operation of the attack (vulnerabilities use, tactics, technics), the scope and the perimeter of compromise
3) Training:
- Knowledge transferring in-house and writing documentation
- in techniques and tools of digital investigation
- methods and tools for analysis (monitoring, training, international conferences, etc.)
**Qualifications**:
**Main requirements**:
Solid knowledge in most of the following technical areas is required, keeping in mind that no one is an expert in every topic.
1) SIEM/SOAR
- Knowledge of the operating principles of Information Monitoring and Security Event Solutions (SIEM).
- Good experience of Splunk and Regex search syntax.
- Good experience of theHive
3) SYSTEM/NETWORK
- Good knowledge of network and system architectures
- Knowledge of the operation of intrusion detection probes and event log correlation tools
4) SECURITY:
- Good knowledge of Mitre Attack framework and counter measures link to the technics and tactics
- Good knowledge of Information monitoring and analysis tools and methods.
- Good knowledge of the security standards for different technologies (web servers, messaging, database, DNS, proxy, firewall, etc.)
- Have a good knowledge on one or more of the following topics:
- Malware types (rootkit, ransomware, botnet, etc.)
- Obfuscation and persistence technics (cryptography, packing, etc.).
- Digital investigation/analysis tools
- SandBox behavioral
**Other requirements**:
- Good level of English - minimum B2 level;
- Good level of French - minimum B1 level;
- Ability to keep up with a demanding and fast-paced environment;
- Good communication skills;
- Good priority definition skills;
- Know how on implementing pedagogy methods;
- Ability to work in a team.
Additional Information
**Few other things you should know**:
This career opportunity is based in Porto, right in the heart of the city, and offers a hybrid working model.
Last but not least, we invite you to discover what a day in your like could look like:
Early morning. Campo 24 de Agosto. In 4 minutes, you are clocking in at the office. Start your day having breakfast with the Team and grab fresh fruit on the way to your seat, in one of Porto’s most typical neighborhoods. This Purple Day is going to be a busy one: daily meeting ensuring all team members are on the same page regarding work status, priorities and blockers, language class and, just after, a Talent Management meeting with your manager, discussing your career path.
Lunch break. Today, your Team is onboarding newcomers, but also welcoming French colleagues: the perfect excuse to walk downt
-
SOC Analyst L2
Há 6 dias
Porto, Portugal Alongside Tempo inteiroWe are looking for a SOC Analyst L2 to join a project at a company specializing in the management of financial markets. The ideal candidate will have solid experience in cybersecurity, with a strong focus on threat hunting and defining rules for SIEM and EDR solutions. You will play a key role in detecting, investigating, and responding to security...
-
SOC Analyst L2
Há 4 dias
Porto, Portugal Natixis in Portugal Tempo inteiroCompany Description Natixis in Portugal is fully integrated in the global organization of Natixis, a French multinational financial services firm specialized in Asset & Wealth Management, Corporate & Investment Banking, Insurance and Payments. A subsidiary of Groupe BPCE, Natixis counts nearly 16.000 employees across 38 countries. Based in Porto, Natixis...
-
SOC Analyst L2: Threat Hunting
4 semanas atrás
Porto, Portugal Alongside Tempo inteiroA financial markets management company in Porto is seeking an experienced SOC Analyst L2. The ideal candidate will focus on cybersecurity, specifically threat hunting and SIEM/EDR rules definition. Responsibilities include monitoring security alerts, conducting threat hunting, and collaborating with IT teams to improve security posture. This role offers a...
-
SOC Analyst L2
2 semanas atrás
Porto, Portugal Alongside Tempo inteiroWe are looking for aSOC Analyst L2to join a project at a company specializing in the management of financial markets. The ideal candidate will have solid experience in cybersecurity, with a strong focus on threat hunting and defining rules for SIEM and EDR solutions. You will play a key role in detecting, investigating, and responding to security threats,...
-
SOC Analyst
2 semanas atrás
Porto, Portugal NOESIS PORTUGAL Tempo inteiroA Noesis procura profissionais para a sua equipa de SOC com o seguinte perfil: **Função**: - Monitorização proativa de intrusões, ataques e padrões de comportamento anómalo - Investigação e enriquecimento de eventos de segurança - Mitigação de risco através de mecanismos de remediação rápida - Coordenação de resposta a incidentes em...
-
SOC Analyst
Há 4 dias
Porto, Portugal Strativ Group Tempo inteiroSOC Analyst Full-time Competitive salary Client location: Portugal Can work remote across Europe The Role A growing technology-led organisation is looking for a SOC Analyst to join a small, hands-on security function. This role combines security monitoring, incident response, and cloud security , with exposure to governance and compliance activities....
-
SOC Analysts
2 semanas atrás
Porto, Portugal SECURNET Tempo inteiroA Securnet fundada em 2002 com a missão de colocar organizações “Always online, Always Secure”, evoluiu desde há uma década para uma completa oferta de soluções e serviços orientados a infraestruturas de IT numa estratégia ratificada pelos próprios clientes. Estamos a contratar SOC Analysts para o Porto. Se estás interessado/a numa carreira,...
-
Hybrid SOC Analyst: Detect, Respond
3 semanas atrás
Porto, Portugal DataSmart Tempo inteiroUma empresa de consultoria reconhecida em Portugal procura um SOC Analyst para se juntar à sua equipe em Porto. O candidato ideal deve possuir um bacharelado em Ciência da Computação ou Segurança da Informação e ter mais de 2 anos de experiência em serviços SOC. Serão valorizados conhecimentos em ferramentas SIEM e EDR, além de proficiência em...
-
soc
1 semana atrás
Porto, Porto, Portugal Welvaart Tempo inteiroAbout WelvaartOn a daily basis, we assumecommitmentsand present solutions to our stakeholders in order to create a structure of human values, based onprofessionalism,honestyandrigor. With a management based onHuman Centered Design, we take care of our professionals with consistentcareer plans, but flexible with their needs and expectations of evolution. Our...
-
Senior SOC Analyst
Há 5 dias
Porto Salvo, Lisboa, Portugal Hays Tempo inteiroPrincipais responsabilidadesTerás como principal responsabilidade a gestão da equipa de SOC, que monitoriza e responde a incidentes de segurança para vários clientes a nível nacional. Passará também por ti a análise de alertas e resposta a tickets de maior complexidade.Para quem vais trabalharO nosso cliente é uma empresa de consultoria tecnológica...