Job updated 17 days ago
The employer was active 7 days ago

Job Description


Role Overview

The L2 Security Engineer is the core investigation and response specialist. This role handles escalated incidents from the L1 team, performing deep-dive analysis, correlating data from multiple sources, and executing initial containment measures. They are also responsible for mentoring L1 engineers and improving detection processes.

Key Responsibilities

1.Conduct in-depth investigations of complex security incidents.

2.Analyze logs from diverse sources (endpoints, network, cloud, identity) to determine the scope and impact of an attack.

3.Perform initial incident response and containment actions (e.g., isolating a host, blocking an IP).

4.Develop and refine detection rules, queries, and operational playbooks.

5.Mentor L1 Engineers and act as a point of escalation for technical questions.

6.Contribute technical details and analysis for customer-facing incident reports.

    Requirements

    Required Qualifications

    1.3-5 years of experience in a SOC, with at least 1-2 years in an incident analysis/response role.

    2.Strong proficiency with XDR platforms, SIEM query languages, and network/endpoint forensic tools.

    3.Deep understanding of MITRE ATT&CK TTPs (Tactics, Techniques, and Procedures).

    4.Experience with network packet analysis (e.g., Wireshark).



      Preferred Skills & Certifications

      • EC-Council Certified Incident Handler (ECIH)
      • EC-Council Computer Hacking Forensic Investigator (CHFI)
      • ISC² SSCP or CISSP (Certified Information Systems Security Professional)
      • Experience with cloud security (AWS, Azure, GCP).

      Interview process


      ※ 自由系統第一階段面談皆為Microsoft Teams視訊面談。

      5
      3 years of experience required
      40,000 ~ 100,000 TWD / month
      Optional Remote Work
      Personal Invitation Link
      This is your personal referral link for job invitation. You'll receive an email notification when someone applied for the position via your job link.
      Share this job

      About us

      自由系统成立於2002年(創櫃板股票代號:7503),我們是由一群充滿熱情的顧問及資訊工程師組織成的專業團隊。

      ◆我們的成立宗旨精神:協助企業解決最惱人的資訊問題。

      ◆我們的服務內容包含:基礎資訊架構維運、雲端平台管理、資訊安全管理及專案資訊顧問服務等資訊專業服務。

      ◆我們的服務目標著重:將企業客戶的商業實務需求、長期發展目標、資訊安全標準納入服務規畫考量,以協助企業主降低營運成本與風險。

      自由系統是一間高速成長的公司,有別於坊間的電腦公司或系統整合商,我們首創市場獨有的訂閱式資訊專業服務,撇棄以購買軟硬體解決問題的傳統思維,相信「專業服務」才能解決客戶問題。

      我們正在找具備下列特質的你(妳):

      ◆不想讓無限的可能性受限於年齡、資歷

      ◆不想屈就於穩定而缺乏挑戰的工作環境

      ◆不想安於現況而失去自我實現的動力

      我們兼有新創公司的自由開放文化,和穩健成長的商業模式,歡迎對「自己」有信心、勇於接受挑戰的「你(妳)」加入自由系統!