Cyber Security Analyst (SOC), Information Security Department
Published on:
Valid until:
Who we are – WE ARE:
Leaders in innovation and a favorite brand of thousands of Bulgarians
Different and we encourage diversity - this gives us invaluable advantages
Flexible, operational and without barriers in the organization and internal communication
What makes us different - THE UNIQUE TEAM OF:
Colorful, interesting and valuable personalities
Professionals striving for the maximum
Like-minded people who like, support and value each other
Contribution and key responsibilities:
Security Monitoring: Monitor and analyse security events across the Bank’s technology environment, separating real threats from noise and spotting suspicious activity before it becomes an incident.
Cyber Threat Investigation: Investigate logs, alerts and indicators of compromise, connect the dots and uncover what happened, how it happened and what was affected.
Incident Response & Management: Take an active role in the analysis, escalation, containment and remediation of cybersecurity incidents, working closely with other technical teams.
Detection Improvement: Review and improve SOC/SIEM use cases, detection rules and monitoring capabilities to stay ahead of evolving attack techniques.
Security Testing: Participate in penetration tests, vulnerability assessments and security investigations to identify weaknesses before attackers do.
Security Innovation & Continuous Improvement: Bring ideas, automate where possible and help evolve security processes, controls and ways of working across the Information Security function.
For efficiency and effective role performance:
A degree in IT, Computer Engineering, Cybersecurity or a related field, with at least 1 year of relevant experience.
Understanding of cyber threats, attack techniques, and information security principles, with the ability to analyse security events, logs, and alerts to identify and investigate potential security incidents.
Solid knowledge of Windows/Linux environments, networking, protocols and the OSI model.
Experience with SIEM and familiarity with security technologies such as DLP, WAF, NGFW, IDS/IPS, Email Security or MDM.
Basic scripting skills and familiarity with relational databases such as Oracle, MySQL or MSSQL are considered an advantage.
Strong analytical skills, curious and proactive mindset, strong attention to detail, teamwork skills and good command of English.
Prospects and opportunities:
To be successful and receive recognition - with us, the path from a personal initiative to a working practice is quick and short
To feel understanding and support – every day we build and preserve the pleasure of our work together