Skip to content
Punggawa Cybersecurity logo

Security Operation Center L1-L3

Punggawa Cybersecurity
WFO
Contract
50 openings

How you will be assessed

  • Punggawa Cybersecurity approves a written scoring rubric for this role before any application is read.
  • Every applicant is scored against that same rubric, with written reasoning recorded for each criterion.
  • Scores rank and explain — they do not decide. A person at Punggawa Cybersecurity chooses who advances, and no application is rejected automatically.

Interested in this role?

Submit your application to Punggawa Cybersecurity.

Apply for this role
About the role

SOC L1

  • Monitor and analyze security alerts from various tools and systems.
  • Perform initial triage and escalation of security incidents.
  • Investigate and validate security events.
  • Document incidents and maintain records in the ticketing system.
  • Collaborate with team members to respond to security incidents.
  • Support threat intelligence updates and improve detection rules.
  • Follow security procedures and ensure compliance with policies.

SOC L2

  • Investigate and analyze security incidents.
  • Perform incident triage and root cause analysis.
  • Correlate logs from multiple security platforms.
  • Escalate complex incidents and provide technical recommendations.
  • Conduct threat hunting and improve detection rules.
  • Create incidents reports and documentation.
  • Mentor SOC L1 analysts when required.

SOC L3

  • Lead and manage complex incident investigations and responses.
  • Conduct advance threat hunting and proactive threat detection.
  • Analyze threat, build detection rules, and tune security controls.
  • Perform malware analysis and forensic investigations.
  • Develop and improve SOC processes, playbooks, and use cases.
  • Collaborate with other teams and provide expert guidance.
  • Mentor and coach L1 and L2 analysts.
  • Prepare executive reports and security recommendations.
Requirements

SOC L1

  • Min. Bachelor's Degree (S1) in Information Technology, Computers Science, Information Security or related field.
  • Minimum 1-2 years of experience in SOC or IT Security Operations.
  • Basic understanding of networking (TCP/IP), security concepts, windows & linux, SIEM tools.
  • Familiar with log monitoring, threat intelligence (basic), incident handling.
  • Good analytical skills and attention to detail.
  • Willing work in shifts and onsite.
  • Certification are a plus: CompaTIA Security+, CEH, CySA, Google Cybersecurity, Microsoft SC-900.

SOC L2

  • Min. Bachelor's Degree (S1) in Information Technology, Computers Science, Information Security or related field.
  • Minimum 3 years of experience as a Security Operation Center (SOC) Analyst.
  • Strong knowledge of: SIEM (e.g., Spulnk, QRadar, Sentinel), EDR/XDR, IDS/IPS, Firewall, Windows & Linux, TCP/IP Networking
  • Experience with: MITRE ATT & CK, Cyber Kill Chain, Threat Intelligence, IoCs/TTPs.
  • Willing work onsite.
  • Certification are a plus: CEH, ComTIA Security+, CySA+, CHFI, GCIA.

SOC L3

  • Min. Bachelor's Degree (S1) in Information Technology, Computers Science, Information Security or related field.
  • Minimum 5 years of experience in SOC or cybersecurity with at least 2 years in a senior role (L2/L3).
  • Strong expertise in: SIEM (e.g., Spulnk, QRadar, Sentinel), EDR/XDR, IDS/IPS, Firewall, Network Security, Malware Analysis, Cloud Security (AWS/Azure/GCP).
  • Experience in: Advance Threat Hunting, Incident Response & Handling, Forensics (network, endpoint).
  • Willing to work onsite.
  • Certification are a plus: CISSP, GIAC (GCIA, GCIH, GCTI), OSCP, CISM, CEH.