Job descriptions & requirements
About CyberDome
CyberDome is a leading Managed Security Services Provider (MSSP) in Nigeria, delivering Managed SOC, MDR, Red Team, Digital Forensics & Incident Response (DFIR), and professional cybersecurity services to enterprise and government clients.
Role Summary
The L1 SOC Analyst provides first-line security monitoring, alert triage, investigation, and incident escalation within the Security Operations Centre.
The role focuses on continuous surveillance of security events, identifying suspicious activities, conducting first-level investigations, and ensuring timely escalation to L2/L3 teams in accordance with approved playbooks, SOPs, and SLAs.
The L1 SOC Analyst plays a critical role in maintaining CyberDome’s 24/7 security monitoring and detection coverage while supporting the cybersecurity posture of our clients.
MUST-HAVES
Applicants must meet the following requirements:
- Must be willing and able to relocate to Abuja.
- Must be willing and available to work on a 24/7 rotational shift schedule, including day shifts, night shifts, weekends, and public holidays.
- Must possess a strong interest in cybersecurity and Security Operations Centre activities.
- Must demonstrate strong analytical, communication, and documentation skills.
- Must be able to work effectively under pressure and comply with defined SOC processes, escalation procedures, and SLAs.
Key Responsibilities
1. Security Monitoring & Alert Handling
- Monitor SIEM dashboards, security alerts, and log sources in real time using platforms such as Securonix, Splunk, Rapid7 InsightIDR, and IBM QRadar.
- Perform initial triage of security alerts based on severity, context, and defined SOPs.
- Validate alerts and distinguish between false positives and true-positive security events.
- Escalate confirmed or suspicious incidents to L2/L3 Analysts and the SOC Lead when escalation thresholds are met.
2. Incident Response Support
- Conduct first-level investigations of suspicious activities such as brute-force attempts, malware detections, suspicious authentication, privilege misuse, and other security events.
- Gather relevant evidence and document investigation findings accurately in JIRA.
- Execute approved basic containment actions, where permitted, such as host isolation, IOC blocking, or account disabling in accordance with established playbooks.
3. Log Management & Reporting
- Review and analyse logs from endpoints, servers, network devices, cloud platforms, authentication systems, and applications.
- Monitor the health and availability of configured log sources and identify ingestion or visibility issues within the SIEM.
- Generate daily SOC shift reports, incident updates, and comprehensive shift handover documentation.
4. Threat Intelligence Consumption
- Review threat intelligence feeds and correlate Indicators of Compromise (IOCs) against observed security events.
- Conduct basic reputation and IOC enrichment using approved threat intelligence platforms.
- Report emerging threats, recurring patterns, and unusual activities to L2/L3 Analysts for further investigation.
5. Compliance & Operational Duties
- Adhere strictly to SOC SOPs, runbooks, playbooks, escalation matrices, and SLAs.
- Maintain accurate incident documentation, investigation timelines, evidence, and analyst notes.
- Participate fully in the SOC rotational shift schedule covering days, nights, weekends, and public holidays.
- Maintain proper shift discipline and ensure effective handover between SOC teams.
Required Skills & Competencies
Technical Skills
- Foundational understanding of cybersecurity concepts including the CIA Triad, common attack vectors, vulnerabilities, threats, and malware categories.
- Basic knowledge of Windows, Linux, and networking fundamentals, including TCP/IP, DNS, HTTP/HTTPS, VPNs, ports, protocols, and authentication concepts.
- Experience or familiarity with SIEM platforms such as Securonix, Splunk, Rapid7 InsightIDR, or IBM QRadar.
- Ability to interpret logs from endpoints, servers, firewalls, authentication systems, network devices, and cloud environments.
- Basic understanding and awareness of the MITRE ATT&CK Framework.
- Basic knowledge of common cybersecurity attacks such as phishing, brute-force attacks, malware, credential attacks, privilege escalation, and suspicious network activity.
Soft Skills
- Strong analytical and problem-solving abilities.
- High attention to detail and accuracy.
- Ability to work effectively under pressure and within strict SLAs.
- Excellent written and verbal communication skills.
- Strong documentation and reporting abilities.
- Ability to follow established instructions, processes, and escalation procedures.
- Willingness to learn and continuously develop technical cybersecurity skills.
- Ability to collaborate effectively within a team-based SOC environment.
Key Performance Indicators (KPIs)
- Accuracy and quality of security alert triage.
- Adherence to response and escalation SLAs.
- Quality and completeness of JIRA incident documentation.
- Compliance with SOC processes, SOPs, and shift discipline.
- Timeliness of incident escalation.
- Quality of SOC shift reports and handover documentation.
- Reduction in unnecessary or false-positive escalations through effective triage.
Tools & Technologies Familiarity – Preferred
- SIEM: Securonix, Splunk, Rapid7 InsightIDR, IBM QRadar
- EDR/XDR: CrowdStrike Falcon, Sophos, Microsoft Defender for Endpoint
- Ticketing: JIRA
- Threat Intelligence: VirusTotal, AbuseIPDB, AlienVault OTX, ANY.RUN
- Operating Systems: Windows and Linux
- Networking: TCP/IP, DNS, HTTP/HTTPS, VPN, Firewall and Proxy Logs
Work Arrangement
- Location: Abuja, Nigeria
- Applicants must be willing to relocate to Abuja.
- This is a 24/7 SOC role requiring rotational day, night, weekend, and public holiday shifts.
Compensation
NGN 400,000.00 net monthly
(Four Hundred Thousand Naira Only)
<
Important safety tips
- Do not make any payment without confirming with the Jobberman Customer Support Team.
- If you think this advert is not genuine, please report it via the Report Job link below.