Job Title
SOC Analyst – Level 1 (L1)
Department
Cybersecurity / Security Operations Center (SOC)
Reports To
SOC Senior Engineer
Location
Iraq, Baghdad
Job Summary
We are seeking a motivated and detail-oriented SOC Analyst - Level 1 to join our Security Operations Center team. As an entry-level cybersecurity professional, you will be the first line of defense against cyber threats, responsible for monitoring, analyzing, and responding to security alerts in real time. This role provides an excellent opportunity to build foundational skills in threat detection, incident response, and security operations within a dynamic 24/7 environment.
Key Responsibilities
Daily Operations & Monitoring
- Monitor SIEM (Security Information and Event Management) dashboards and security alerts from various sources (IDS/IPS, EDR, firewalls, network devices)
- Perform initial triage and classification of security events to determine validity and urgency
- Conduct basic log analysis and network traffic monitoring to identify suspicious activities
- Follow predefined runbooks and playbooks for standard security incidents
Incident Response & Investigation
- Assist in the initial investigation of potential security incidents
- Escalate confirmed threats and complex incidents to Tier 2/3 analysts according to SLAs
- Document security events, prepare incident reports, and maintain detailed case records
- Participate in malware analysis, vulnerability assessments, and basic forensic investigations as directed
Threat Intelligence & Security Awareness
- Support threat intelligence gathering and security event correlation
- Stay current on emerging cyber threats, attack techniques, and security trends
- Assist in the development and improvement of security procedures and playbooks
- Collaborate with senior analysts and security engineers to enhance overall defenses
Teamwork & Communication
- Work collaboratively with SOC team members and other IT departments
- Communicate effectively regarding security incidents and their status
- Participate in shift handovers and ensure continuity of operations
Qualifications & Skills
Must-Have Requirements
- 0-2 years of experience in cybersecurity, IT operations, or a related field
- Basic knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, firewalls)
- Familiarity with common cyber threats, attack vectors, and security concepts
- Understanding of security tools and technologies (SIEM, IDS/IPS, EDR, antivirus)
- Strong analytical skills with attention to detail
- Ability to work effectively in a fast-paced, high-pressure environment
- Excellent written and verbal communication skills
- Willingness to work in a 24/7 rotating shift schedule (including nights, weekends, and holidays)
Preferred Tools Experience
Experience with one or more of the following is an advantage:
- Microsoft Sentinel
- Splunk
- Microsoft Sentinel
- SentinelOne
- Fortinet security platforms
- ServiceNow, Jira, or other SOC/ticketing platforms
Education & Certifications
- Bachelor's degree or diploma in Cybersecurity, Information Security, Computer Science, Information Technology, Networking, or a related field.
- Relevant certifications are an advantage, such as:
- CompTIA Security+
- CompTIA CySA+
- Other recognized SOC or security certifications
How to Apply
Please submit your resume and cover letter highlighting your relevant experience and interest in cybersecurity to info@cybercodetech.com