L3 SOC Analyst - Rome

L3 SOC Analyst - Rome

Roma Full-Time 70000 - 90000 € / anno (stimato) Smart working non possibile
Integrity360

In sintesi

  • Mansioni: Fornire supporto tecnico avanzato per indagini di sicurezza complesse e ad alto impatto.
  • Azienda: Integrity360, leader nella cybersecurity con una cultura collaborativa.
  • Benefit: Opportunità di crescita professionale, formazione continua e un ambiente dinamico.
  • Altre informazioni: Possibilità di mentoring e sviluppo tecnico per analisti junior.
  • Perché questo lavoro: Lavora con tecnologie all'avanguardia e fai la differenza nella sicurezza informatica.
  • Qualifiche: Esperienza in operazioni di sicurezza e capacità di analisi delle minacce.

La retribuzione prevista è compresa tra 70000 - 90000 € per anno.

About Us

Integrity360 is a leading independent cybersecurity and PCI specialist operating across Europe, Africa, the Caribbean, and North America.

The company has office locations in Ireland, the UK, Bulgaria, Italy, Sweden, Spain, Lithuania, Ukraine, Africa, the Caribbean, and Canada, supported by six Security Operations Centres (SOCs) located in Dublin, Sofia, Madrid, Stockholm, Rome, and Cape Town.

With over 780 employees, including more than 585 dedicated cybersecurity professionals, Integrity360 delivers a full suite of professional, support, and managed security services.

These span the complete cyber risk lifecycle, from identification and prevention to detection, response, and recovery.

Integrity360 supports over 3000 mid‑market and enterprise organisations across sectors including financial services, insurance, government, healthcare, retail, telecommunications, and utilities.

At Integrity360, people come first.

We invest heavily in learning, development and progression, fostering a dynamic culture where innovation, collaboration and continuous growth are at the heart of what we do.

If you're ready to take your cyber security career to the next level, we’d love to hear from you.

Job Role / Responsibilities

In this role, you will act as a Level 3 escalation point within the MDR/SOC function, providing advanced technical support to Level 2 analysts during complex or high‑severity investigations.

You will be expected to bring deep operational knowledge across modern security technologies, including SIEM, EDR, Network Intrusion Detection Systems, SOAR, DLP and related security monitoring platforms.

The Principal SOC Analyst will support the investigation, containment and remediation of advanced threats, ensuring that incidents are analysed in the correct business and technical context.

The role requires strong hands‑on experience in security operations, incident response, threat analysis and detection tuning, as well as the ability to work directly with customers and internal stakeholders to improve detection capability and strengthen cyber security posture.

You will contribute to the continuous improvement of the MDR service by supporting the definition of security monitoring strategies, improving detection logic, tuning security technologies, reviewing investigation processes and advising customers on technical optimisation opportunities.

A strong understanding of malware behaviour, adversary tactics, techniques and procedures, and emerging threats will be critical to success.

Primary Duties/Responsibilities include

  • Act as the Level 3 escalation point for advanced, complex or high‑impact security investigations.
  • Support Level 2 analysts during complex investigations, providing technical guidance, validation and direction.
  • Perform in‑depth analysis of security events, alerts, logs, endpoint telemetry, network traffic and other relevant data sources.
  • Lead advanced incident investigations, including scoping, containment, eradication and remediation recommendations.
  • Analyse malicious activity, suspicious files, attacker behaviour and adversary TTPs.
  • Support customers from a technical perspective in the optimisation, tuning and improvement of their security monitoring capabilities.
  • Review and improve SIEM, EDR, NIDS, SOAR and other security tool configurations to reduce false positives and improve detection quality.
  • Contribute to the development and refinement of detection use cases, correlation rules, alerting logic and investigation playbooks.
  • Support the definition of customer security monitoring strategies based on risk profile, threat landscape and available telemetry.
  • Provide technical recommendations to strengthen customer cyber security posture and improve resilience against current and emerging threats.
  • Conduct threat hunting and proactive analysis based on indicators, behaviours, intelligence and attack patterns.
  • Document investigation findings, evidence, timelines, containment actions and remediation recommendations in a clear and structured manner.
  • Prepare and deliver technical reports to customers, partners and internal stakeholders.
  • Monitor trusted sources for emerging threats, vulnerabilities and adversary activity relevant to customer environments.
  • Contribute to the continuous improvement of SOC processes, procedures, documentation and knowledge base material.
  • Support mentoring and technical development of Level 1 and Level 2 analysts where required.
  • Desired Skills
  • Strong hands‑on experience in Security Operations Centre or MDR environments.
  • Deep operational knowledge of SIEM, EDR, Network Intrusion Detection Systems, SOAR, DLP and related security monitoring technologies.
  • Strong experience with security event triage, correlation, investigation and escalation.
  • Ability to analyse endpoint, network, identity, cloud and application telemetry in support of complex investigations.
  • Experience with SIEM query languages and detection logic, such as KQL, SPL, Sigma or equivalent.
  • Experience tuning security controls and detection content to improve alert fidelity and reduce false positives.
  • Strong understanding of attacker tactics, techniques and procedures, including MITRE ATT&CK.
  • Ability to perform host‑based and network‑based threat analysis.
  • Experience analysing packet captures, endpoint artefacts, logs, scripts, documents and potentially malicious files.
  • Strong understanding of incident response lifecycle, including preparation, identification, containment, eradication, recovery and lessons learned.
  • Strong understanding of enterprise network architecture, TCP/IP, firewalls, proxies, VPNs, DNS, email security and cloud environments.
  • Understanding of security protocols, encryption technologies and common authentication mechanisms.
  • Experience supporting customer‑facing technical discussions, including investigation reviews, tuning recommendations and posture improvement activities.
  • Ability to manage multiple complex incidents and make effective decisions under pressure.
  • Strong written and verbal communication skills, with the ability to explain technical findings to both technical and non‑technical stakeholders.
  • Experience with Microsoft Sentinel, Microsoft Defender, Splunk, QRadar, Crowd Strike, Sentinel One, Palo Alto, Suricata, Zeek, Snort or similar technologies is highly beneficial.
  • Experience with cloud security monitoring across Microsoft Azure, AWS or Google Cloud is beneficial.
  • Experience with threat hunting, detection engineering or purple team activities is beneficial.
  • Ability to produce clear technical documentation, investigation reports and customer‑facing recommendations.

Certifications/Qualifications

  • Security industry certifications such as GCIH, GCFA, GCIA, GNFA, GCTI, GSEC, CISSP, Cy SA+, SC‑200, AZ‑500 or equivalent are highly beneficial.
  • Minimum 2–3 years of experience in a SOC, MDR, incident response, CSIRT or cyber security operations role.
  • Proven experience handling complex security incidents and supporting advanced investigations.
  • Working knowledge of SIEM, EDR, SOAR, NIDS, DLP and threat intelligence platforms.
  • Experience working with threat hunting methodologies and security detection frameworks.
  • Experience supporting customers or internal stakeholders with security optimization, detection tuning and cyber security posture improvement.
  • #J-18808-Ljbffr

L3 SOC Analyst - Rome datore di lavoro: Integrity360

Integrity360 è un datore di lavoro eccezionale, offrendo un ambiente di lavoro stimolante e collaborativo a Roma, dove l'innovazione e la crescita continua sono al centro della nostra cultura aziendale. Investiamo attivamente nello sviluppo professionale dei nostri dipendenti, fornendo opportunità di apprendimento e progressione in un settore in rapida evoluzione come la cybersecurity. Con un forte focus sulla sicurezza e il supporto ai clienti, i nostri analisti SOC di livello 3 possono contribuire a migliorare le capacità di rilevamento e la postura di sicurezza dei nostri clienti, rendendo ogni giorno significativo e gratificante.

Integrity360

Dettagli di contatto:

Team di recruiting di Integrity360

Consigli degli esperti StudySmarter🤫

Ecco come pensiamo che potresti ottenere L3 SOC Analyst - Rome

Unisciti a gruppi di cybersecurity

Cerca di entrare a far parte di gruppi e comunità locali o online dedicate alla cybersecurity. Partecipa a forum, come quelli su Reddit o Discord, dove le persone discutono le ultime novità del settore e condividono opportunità di lavoro. Essere attivo in queste comunità può farti conoscere e magari ottenere informazioni su posizioni aperte.

Metti in mostra le tue skill

Considera di contribuire a progetti open-source legati alla cybersecurity. Avere un portfolio online che dimostri le tue capacità tecniche e i progetti a cui hai lavorato può darti un vantaggio. Inoltre, questo tipo di esperienza è spesso molto apprezzata dai datori di lavoro nel campo.

Eventi e conferenze

Non perdere l'occasione di partecipare a conferenze e eventi di cybersecurity come Black Hat o DEF CON. Questi eventi sono fantastici per il networking e per conoscere di persona i professionisti del settore. Se un'azienda come Integrity360 è presente, assicurati di visitare il loro stand e di connetterti con i reclutatori.

Candidati direttamente

Applica direttamente sul sito di Integrity360! Spesso, le aziende preferiscono le candidature ricevute tramite il loro portale ufficiale. Non dimenticare di personalizzare la tua candidatura e dimostrare il tuo interesse per il loro team di cybersecurity. Mostrati proattivo e motivato.

Pensiamo che ti servano queste competenze per eccellere come L3 SOC Analyst - Rome

Analisi degli eventi di sicurezza
Conoscenza operativa profonda di SIEM
EDR
Sistemi di rilevamento delle intrusioni di rete
SOAR
DLP
Triage degli eventi di sicurezza

Alcuni consigli per la tua candidatura 🫡

Sottolinea le tue Certificazioni:Nel campo della cybersecurity, avere certificazioni come CompTIA Security+, CEH o CISSP può fare la differenza. Assicurati di includerle nel tuo CV e magari di menzionarle anche nella lettera di presentazione per dimostrare che sei aggiornato e serio riguardo al tuo percorso professionale.

Mostra Esperienza Pratica:Raccontaci delle tue esperienze pratiche nel settore! Progetti di sicurezza, stage o anche competizioni di hacking etico possono essere un grande valore aggiunto. Usa il tuo CV per evidenziare case study interessanti o risultati specifici che hai raggiunto.

Personalizza la Tua Lettera di Presentazione:Questa è l'occasione perfetta per spiegare perché sei il candidato ideale per il ruolo di L3 SOC Analyst - Rome presso Integrity360. Parla delle tue passioni per la cybersecurity e di come intendi contribuire alla sicurezza dell'azienda. Stiamo cercando candidati motivati e con voglia di crescere!

Includi Link Utili:Aggiungi al tuo CV link a progetti o articoli tecnici che hai scritto. Se hai un blog, un profilo GitHub con progetti pertinenti o anche profili su piattaforme come LinkedIn, mettili in evidenza. Questo mostra la tua passione e impegno nel settore della cybersecurity!

Come prepararti a un colloquio di lavoro presso Integrity360

Dimostra le tue capacità tecniche

In un colloquio per un ruolo di cybersecurity, possiamo aspettarci domande tecniche specifiche come la gestione di vulnerabilità o la sicurezza delle reti. Fai pratica con le varie tecnologie di sicurezza informatica, e prepara esempi concreti di progetti in cui hai applicato queste tecnologie nel tuo portfolio. Ricorda, è meglio mostrare le tue capacità piuttosto che limitarti a parlarne!

Preparati a casi pratici

Le interviste di cybersecurity spesso includono casi pratici o scenari di incident response. Possiamo essere chiamati a identificare vulnerabilità in un sistema simulato o a risolvere un attacco informatico ipotetico. Esercitati con simulazioni o piattaforme di test per essere pronto a dimostrare il tuo processo di pensiero e le tue decisioni critiche.

Conosci le ultime tendenze

Essere aggiornati sulle ultime tendenze e minacce nel campo della cybersecurity è cruciale. Parla di come hai seguito corsi online o partecipato a conferenze. Questo dimostra al tuo potenziale datore di lavoro, Integrity360, che sei appassionato e proattivo nel tuo percorso professionale.

Sii pronto a parlare di soft skills

In un ruolo di cybersecurity, le soft skills possono essere altrettanto importanti delle competenze tecniche. Considera come hai lavorato in team per risolvere problemi complessi o come hai comunicato efficacemente i rischi alla direzione. Preparati a raccontare storie che evidenziano le tue capacità relazionali e di problem solving, perché nel mondo della cybersecurity, spesso collaboriamo con diverse parti interessate.