Security Analyst SOC
Job Summary
At SITA we keep airports moving airlines flying smoothly and borders open. Our technology and communication innovations power the success of the global air travel industry.
Youll find us in 95% of international airports working closely with over 2500 transportation and government clients. Each partnership brings unique challenges and we thrive on delivering fresh solutions and cutting-edge tech to keep operations running like clockwork. We dont just move the world forwardwere proud to be recognized as aGreat Place to Workby our employees and certified in most of our growing locations.
Here we feel empowered supported and inspired to grow.
Are you ready to love your job The adventure begins right here with you at SITA.
As Security Analyst you will be responsible for monitoring triaging and investigating security alerts and events to support the timely identification and escalation of potential security incidents. You will work closely with the SOC team to protect the organization by following established playbooks procedures and escalation processes.
You will be accountable for validating security alerts conducting initial investigations documenting findings and ensuring that security incidents are escalated appropriately while contributing to continuous improvements in monitoring and operational effectiveness.
Reporting to the Senior Manager Service Operations you will be part of the Security Operations Center (SOC) responsible for monitoring the organizations security posture identifying threats investigating suspicious activity and supporting the broader Cyber Defense function.
- Monitor security alerts and events across SIEM EDR/XDR cloud identity email and other security monitoring platforms.
- Perform initial alert triage and determine whether activity is malicious benign or a false positive.
- Investigate low- to medium-severity security alerts and gather relevant evidence to support response and escalation activities.
- Execute approved SOC playbooks standard operating procedures (SOPs) and investigation workflows.
- Create maintain and update investigation tickets with clear documentation timelines evidence and actions taken.
- Escalate complex high-risk or suspicious cases to Senior Security Analysts SOC SMEs or the Incident Response team as required.
- Participate in shift handovers and operational reporting to maintain investigation continuity and situational awareness.
- Support vulnerability monitoring compliance activities and security operational tasks when required.
- Contribute to knowledge base updates process improvements and SOC operational maturity initiatives.
- Maintain high standards of accuracy professionalism and confidentiality when handling security investigations and sensitive information.
- You have 1-3 years of experience in Security Operations or a related cybersecurity role.
- You have experience investigating security alerts using EDR/XDR solutions such as Microsoft Defender Cortex XDR or CrowdStrike Falcon.
- You have experience using IT service management or ticketing platforms such as ServiceNow to document track and escalate security investigations.
- You possess a fundamental understanding of SIEM technologies preferably Elastic or Splunk.
- You have basic knowledge of Windows Linux Active Directory Azure/Entra ID and networking concepts.
- You understand common cyber threats and attack techniques including phishing malware brute-force attempts suspicious authentication activity and endpoint-based detections.
- You can analyze and correlate security events from multiple data sources to support investigations and alert validation.
- You have a foundational understanding of detection rules correlation logic and monitoring use cases across SIEM and EDR/XDR platforms.
- You possess strong analytical organizational documentation and communication skills with strong attention to detail.
- You hold a Bachelors Degree in Information Technology Cybersecurity Computer Science or a related field and at least one industry-recognized cybersecurity certification such as Security GSEC CySA SC-200 AZ-900 or SC-900.
- Participation in cybersecurity training programs Capture the Flag (CTF) competitions cyber labs or other hands-on learning activities.
- Exposure to cloud security monitoring within Microsoft Azure Microsoft 365 or AWS environments.
- Familiarity with the MITRE ATT&CK framework and its application to security monitoring and threat investigations.
Were all about diversity. We operate in 200 countries and speak 60 different languages and cultures. Were really proud of our inclusive environment. Our offices are comfortable and fun places to work and we make sure you get to work from home too. Find out what its like to join our team and take a step closer to your best life ever.
Flex Week: Work from home up to 2 days/week (depending on your teams needs)
Flex Day: Make your workday suit your life and plans.
Flex-Location: Take up to 30 days a year to work from any location in the world.
Employee Wellbeing: We have got you covered with our Employee Assistance Program (EAP) for you and your dependents 24/7 365 days/year. We also offer Champion Health - a personalized platform that supports a range of wellbeing needs.
Professional Development: At SITA we believe growth fuels innovation. Our learning ecosystem offers access to world-class platforms and programs designed to help you thrive. From LinkedIn Learning Microsofts Enterprise Skills Initiative and Airport Council International -available to all employees-to specialized solutions like Pluralsight for technology upskilling Harvard Business Publishing for people leadership Stanford for strategic development and many others we align learning opportunities with your Development Plan and our business priorities. Your development journey is supported every step of the way.
Competitive Benefits: Competitive benefits that make sense with both your local market and employment status.
SITA is an Equal Opportunity Employer. We value a diverse support of our Employment Equity Program we encourage women aboriginal people members of visible minorities and/or persons with disabilities to apply and self-identify in the application process.
Required Experience:
IC
About Company
At SITA we lead one of the most exciting and advanced industries in the world. With us, there are no limits for people looking to explore the edges of possibility and beyond. We are the world’s leading specialist in air transport communications and information technology. Around the ... View more