Associate SOC Analyst
AI in this role
Job Purpose
Responsible for monitoring and investigating security events, responding to cybersecurity incidents, and supporting threat detection and hunting activities using SIEM and EDR platforms. Assists in developing detection content, identifying monitoring gaps, optimizing alerts, and implementing SOAR automation to improve incident response effectiveness and strengthen the organization's security operations capabilities
Key Result Responsibilities
- Investigate, analyze, and respond to security incidents, perform deep-dive EDR analysis to identify threats, assess impact, and support containment and remediation activities.
- Reduce Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) through effective incident handling, structured investigation workflows, and adherence to response playbooks.
- Write, tune, and optimize detection queries and use cases to enhance threat detection and support proactive threat hunting activities.
- Build and maintain behavior-based detections, identify detection gaps, and implement improvements to strengthen monitoring capabilities.
- Perform alert tuning and rule optimization to reduce false positives and improve detection accuracy
Key Result Responsibilities-Continued
- Conduct threat hunting activities using SIEM, EDR, and security telemetry to identify suspicious activities and emerging threats
- Design, implement, and maintain SOAR playbooks to automate repetitive SOC tasks and improve operational efficiency
- Integrate SOAR platforms with SIEM, EDR, and threat intelligence solutions to streamline end-to-end incident response processes
- Collaborate with SOC analysts, threat intelligence teams, and IT/infrastructure teams during incident investigation, containment, remediation, and continuous improvement initiatives
Qualifications (Academic, training, languages)
- Bachelor’s degree in computer science, Information Technology, Electronics, or a related engineering discipline.
- Demonstrated experience writing and tuning SIEM detection rules with measurable improvement in alert fidelity
- Incident Response, Alert Triage, Threat Hunting, Malware Analysis, Ransomware Investigation
- KQL (mandatory), SPL or equivalent SIEM query language
- SIEM rule creation, behavioral analytics, alert tuning, false positive reduction
- Hands-on experience designing and implementing SOAR playbooks
- Workflow automation for alert enrichment, and automated containment actions
- Practical experience implementing or maintaining SOAR playbooks in a production SOC environment
- Working knowledge of the MITRE ATT&CK framework and its application to detection coverage
- Microsoft SC-200: Security Operations Analyst
- CEH or equivalent incident handling certification
- CompTIA CySA+
- Microsoft Sentinel, Datadog Splunk, Securonix, LogRhythm, or equivalent
- Microsoft Defender, CrowdStrike, or equivalent
Work Experience
With 1–2 years of hands-on experience in a SOC or security operations environment.
How we rate this
Associate SOC Analyst at Air Arabia rates 26 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.
Little AI. AI is not part of the work.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Get new cybersecurity jobs by email
One email a week with the new cybersecurity jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Other roles that involve little AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step