Job description for SOC Engineer at Ogya Tekno Nusantara
Key Responsibilities
• Monitor, analyze, and respond to security alerts and incidents using SIEM and security monitoring tools.
• Investigate cybersecurity threats, malware infections, phishing attacks, and unauthorized access attempts.
• Conduct incident response activities, including containment, eradication, recovery, and post-incident analysis.
• Perform threat hunting and proactive security monitoring to identify emerging risks.
• Analyze network traffic, system logs, and endpoint activities to detect suspicious behavior.
• Coordinate with IT teams to remediate vulnerabilities and security weaknesses.
• Support vulnerability assessments, penetration testing, and security compliance initiatives.
• Prepare incident reports, root cause analyses, and security recommendations.
• Develop and maintain SOC playbooks, standard operating procedures, and security documentation.
• Participate in security awareness and continuous improvement initiatives.
Qualifications
Required
• Bachelor's Degree in Information Technology, Computer Science, Cyber Security, Information Systems, or a related field.
• Minimum 2 years of hands-on experience in a Security Operations Center (SOC), Cyber Security, Incident Response, or Information Security role.
• Strong knowledge of:
o Security Operations and Incident Response
o SIEM platforms (Microsoft Sentinel, Splunk, QRadar, ArcSight, etc.)
o Network Security and Security Monitoring
o Endpoint Detection & Response (EDR)
o Windows, Linux, and Cloud Security
o Threat Intelligence and Threat Hunting
o Vulnerability Assessment and Risk Management
• Understanding of common cyber attack techniques, malware analysis, and digital forensics.
Preferred Professional Certifications
Candidates should possess one or more of the following certifications:
• CISSP (Certified Information Systems Security Professional)
• CISM (Certified Information Security Manager)
• CEH (Certified Ethical Hacker)
• CHFI (Computer Hacking Forensic Investigator)
• CISA (Certified Information Systems Auditor)
Additional cyber security certifications will be considered an advantage.
Required Skills
• Strong analytical and problem-solving abilities.
• Excellent incident investigation and troubleshooting skills.
• Knowledge of MITRE ATT&CK Framework, NIST Cybersecurity Framework, and ISO 27001.
• Ability to work under pressure during security incidents.
• Strong verbal and written communication skills.
• Ability to work collaboratively with technical and non-technical stakeholders.







