
Triage and analyze security alerts, assess threats, and prioritize based on risk and impact Execute incident response procedures and document findings clearly Distinguish false positives from real threats using SIEM and security tools Understand common attack vectors, TTPs, and apply contextual log analysis Collaborate with cross-functional teams to ensure effective incident response Stay updated on emerging threats and security trends Support the SOC team in cybersecurity incident response activities Create, optimize, and fine-tune SIEM alerts to improve detection accuracy Enhance SOC monitoring capabilities through continuous improvement initiatives and automation Contribute to the development of SOC processes, playbooks, and best practices
Bachelor's degree in Computer Science, Engineering, or related field (or equivalent experience). 5+ years of hands-on SOC or information security experience in a global IT environment. Experience with SIEM tools (Graylog, Splunk, ELK, Rapid7, LogRhythm, or QRadar). Experienced with APM Tools (Grafana, Prometheus, NewRelic, DataDog atau DynaTrace) Experienced working in Telco Industry for 5 years related to SOC Relevant certifications (GCIH, GCIA, Splunk/QRadar) are a plus Fluent speaking/writing in Bahasa Indonesia and English Strong UNIX/Linux skills and proficiency in Bash or Python scripting Skilled in RegEx, log parsing, pipeline creation, and data normalization Experience in SIEM tuning, use case development, and alert optimization Familiar with building and enhancing detection rules and threat analytics Exposure to AI/ML for noise reduction and threat detection is a plus
Konsultan
https://www.phincon.com/
622125556178
250-500
monday - friday
Formal
Medical, Miscellaneous allowance, Loans, Dental, Sports (e.g. Gym)
Indonesian
88 @ Kasablanka Office Tower, 18th Floor Jl. Casablanca Raya Kav 88 Tebet Jakarta 12870 Indonesia