About the Role
As a member of Fiserv's Cybersecurity Incident Response Team (CSIRT), the Cybersecurity SOC Analyst supports investigation and response activities for cybersecurity events across the global enterprise environment. The role focuses on alert triage, incident investigation, log analysis, and escalation of confirmed incidents while contributing to global cybersecurity operations.
Responsibilities
- Monitor and triage security alerts and events generated by enterprise security tools.
- Perform initial investigation of suspicious activity across endpoint, network, identity, email, cloud, application, and system log sources.
- Analyze data within SIEM/SOAR platforms originating from EDR, firewalls, proxies, IDS/IPS, email security, and other monitoring tools.
- Determine incident severity, impact, and required response actions.
- Document investigations, findings, actions taken, and escalations in case management systems.
- Follow shift handoff procedures and communicate open issues and emerging threats.
- Identify recurring false positives, process gaps, and opportunities for operational improvements.
Requirements
- Experience in cybersecurity operations, incident response, security monitoring, IT operations, networking, or a related enterprise technology environment.
- Bachelor's degree in Cyber Security, Information Technology, Computer Science, or a related field preferred.
- Ability to support a 24x7x365 operating model.
- Foundational knowledge of network protocols, operating systems, enterprise architecture, and security log sources.
- Understanding of incident response processes, alert triage, threat indicators, and cyber attack techniques.
- Strong analytical, written, and verbal communication skills.
- Ability to prioritize work and follow documented procedures.
- Strong critical thinking, investigative, and problem-solving skills.
Preferred Qualifications
- Security certifications such as Security+, CySA+, CEH, GCIH, or similar.
- Experience with scripting or programming languages.
- Experience with SIEM, SOAR, EDR, IDS/IPS, email security, firewalls, proxy tools, or case management platforms.