Deskripsi pekerjaan SOC Incident Responder PT Lintas Media Danawa
Qualfications :
- Minimum of 3–5 years of dedicated experience working inside a Security Operations Center (SOC) or in a dedicated Incident Response role.
- Demonstrated history of successfully managing, containing, and documenting mid-to-high severity security incidents.
- Availability to participate in an escalated on-call rotation or rotating shift schedule to maintain core operational coverage.
- Preferred Certifications & Education
- Bachelor’s degree in Cybersecurity, Computer Science, Computer Engineering, or equivalent practical field experience.
- Holds or is actively pursuing at least one of the following intermediate security designations:
○ GIAC Certified Incident Handler (GCIH)
○ GIAC Certified Detection Analyst (GCDA)
○ CompTIA Cybersecurity Analyst (CySA+)
○ Certified Computer Security Incident Handler (CSIH)
Responsibilities :
- Deep-Dive Investigation & Contextualization
- Investigate complex alerts escalated by Tier-1 analysts by correlating logs across host endpoints, network traffic, cloud environments, and identity logs.
- Trace attack paths and attacker footprints from initial access to execution, identifying exactly what files, processes, or registry keys were modified.
- Perform basic static and dynamic analysis of suspicious files, scripts, and email attachments to identify Indicators of Compromise (IoCs).
- Active Threat Containment & Response
- Execute authorized containment playbooks during live incidents, including isolating hosts via EDR, revoking compromised user credentials, or blocking malicious IPs at the firewall.
- Review existing standard operating procedures (SOPs) and response playbooks, updating detection logic to reduce future false positives.
- Partner with IT and Infrastructure teams to provide specific, technical remediation advice (e.g., patching, configuration changes) following a security event.
- Mentorship & Technical Elevation
- Provide technical feedback, quality reviews, and coaching to Tier-1 analysts to improve frontline alert logging and screening accuracy.
- Assist Tier-3 analysts in executing targeted threat-hunting hypotheses across the enterprise network based on active threat intelligence feeds.

