Hello,

Sign in to find your next job.

SOC/NOC Tier 1 Analyst

CÔNG TY TNHH GALAXY DIGITAL HOLDINGS

Galaxy Innovation Hub - D1 Road, Hi-Tech Park, District 9, HCMC.

Posted date:

Job level

Experienced (Non - Manager)

Salary

Job Descriptions

Role Overview:

The next-generation SOC/NOC Tier 1 serves as the first line of defense in the security and operations monitoring model, working with alerts that have been pre-processed by AI (AI-triaged alerts).
The role focuses on validation, accurate classification, reducing false positives, and ensuring proper escalation to Tier 2/3 teams.

Key Responsibilities:

Monitoring & Handling AI-Triaged Alerts:

  • Monitor and handle SOC/NOC alerts that have been preliminarily classified by AI.
  • Re-check the accuracy of:
    • Security alerts
    • Operational alerts
  • Determine the severity level (Severity Validation).
  • Perform triage according to standardized playbooks.
  • Escalate critical events to the Tier 2 or Incident Response (IR) team.

False Positive Validation:

  • Analyze logs and perform event correlation to determine:
    • False Positive
    • Benign True Positive
    • Malicious Activity
  • Compare findings with the system baseline.
  • Record notes and update information to support detection tuning.
  • Collaborate with Detection Engineers to improve detection rules.

SIEM System Usage & Operations:

  • Be proficient in using Elasticsearch within a a SIEM environment.
  • Query logs using:
    • KQL / DSL queries
  • Review:
    • Authentication logs
    • Network logs
    • Application logs
  • Search for Indicators of Compromise (IOC) and abnormal patterns.

Required Foundational Knowledge:

Computer Networking

  • TCP/IP, OSI model
  • DNS, HTTP/HTTPS, SMTP
  • Firewall, IDS/IPS
  • VPN, NAT

Network Security

  • Brute force attacks
  • Port scanning
  • Lateral movement
  • C2 traffic
  • Basic threat patterns

Application Security

  • Understanding of the OWASP Top 10.
  • Ability to identify:
    • SQL Injection
    • Cross-Site Scripting (XSS)
    • Broken Authentication
    • Remote Code Execution (RCE)
  • Ability to read and understand application logs related to security vulnerabilities.

Job Requirement

Experience

  • Students or graduates majoring in Information Security or Information Technology are preferred.
  • Having personal hands-on labs or practical security environments is an advantage.

Technical Skills

  • Ability to use SIEM tools (Elasticsearch is a plus).
  • Ability to read and analyze basic logs.
  • Ability to write log search queries.
  • Understanding of basic Incident Response processes.
  • Strong analytical thinking and the ability to avoid “blind trust” in AI outputs.

Soft Skills

  • Careful and detail-oriented.
  • Critical thinking mindset.
  • Ability to work in shifts (shift-based).
  • Clear documentation and reporting skills.
Proposed KPIs:
  • False Positive validation accuracy ≥ 95%.
  • Average alert handling time (MTTA).
  • Correct escalation rate.
  • Number of rule improvement proposals per quarter.
  • Compliance with established processes and playbooks.
Benefits:
  • Competitive salary package (Base salary and performance bonuses).
  • Probation period salary is 100% of the official salary.
  • Comprehensive health and accident insurance.
  • 15 days of annual leave, 3 remote work days per month.
  • Provision of work equipment (Macbook/ Laptop, mouse, monitor, etc.).
  • A creative and modern working environment.

More Information

  • Degree: Bachelor
  • Age: Unlimited
  • Type of employment: Permanent

You should be skill

Apply for:

Your Contact Information

Your resume

Upload resume (Only supports *.doc, .*docx, *.pdf and less than 3 MB).

Choose file other source (Dropbox)

CareerViet.vn - Mạng Việc làm & Tuyển dụng lớn nhất thế giới

Công Ty Cổ Phần CareerViet Trụ̣ sở: 139 Pasteur, Phường Võ Thị Sáu, Quận 3, TP.HCM

MST: 0303284985Ngày cấp: 25/04/2013 Nơi cấp: Sở Kế Hoạch Và Đầu Tư Thành Phố Hồ Chí MinhĐiện thoại: (84.28) 3822-6060 Email: contact@careerviet.vn