SOC
L1 SOC Analyst Intern.
Work the live client queue from your first shift, not a sandbox. Every alert you triage is a real client’s decision, and by month 4 the shift could yours to run alone.
Zentara Technologies HQ, Serpong·Internship·On-site
The role
Zentara is opening a 6-month L1 SOC Analyst internship program to add first-line capacity to its 24/7 Managed SOC. Interns take on business-as-usual alert handling on a defined schedule, under mentor review, and build toward independent shift work by month 4.
The work runs inside the SIEM. Each intern works the alert queue, applies written runbooks, records every decision in a ticket, and escalates to L2 through a fixed escalation path. A named L2 mentor reviews closed tickets throughout the program.
The result is more queue coverage for client environments, tighter adherence to response SLAs, and a pool of analysts already trained on Zentara's procedures.
What you will do
- Monitor the SIEM alert queue and acknowledge each alert inside the response window for its severity.
- Triage alerts and classify each as true positive, false positive, or benign. Record the evidence behind every verdict.
- Enrich indicators such as IP addresses, domains, URLs, and file hashes using approved threat intelligence sources and SIEM context.
- Escalate confirmed and unresolved incidents to L2 through the defined escalation path. Each escalation carries a complete ticket.
- Analyze phishing emails reported by client users and return a documented verdict.
- Check log source health in SIEM and report sources that stop sending events.
- Keep each ticket current with a timeline, evidence, and actions taken.
- Write a handover note at every shift change so the incoming analyst starts with full context.
- Collect and verify data used in the monthly client reports, which run on an executive track and a technical track.
- Report runbook gaps and unclear detection logic to the SOC Lead with a proposed fix.
- Handle client data under Zentara's ISO 27001 information security policies.
What you bring
- Final-year student or graduate within the last 12 months in Computer Science, Information Technology, Information Systems, Cybersecurity, or a related field.
- Working knowledge of TCP/IP, DNS, HTTP and HTTPS, and common service ports.
- Ability to read Windows Event Logs and Linux authentication and syslog entries.
- Understanding of common attack types: phishing, brute force, malware execution, command and control, and lateral movement.
- Awareness of the MITRE ATT&CK tactics and how an alert maps to them.
- Fluent Bahasa Indonesia and professional English. Tickets and handover notes are written in clear, short sentences.
- Availability for the full 6 months, onsite, on a rotating 24/7 shift roster.
Preferred
- CompTIA Security+, CEH, ISC2 Certified in Cybersecurity, or Cisco CyberOps Associate.
- Hands-on SIEM exposure through coursework or a home lab, such as Wazuh, Elastic, or Splunk.
- Public lab or CTF activity on platforms such as TryHackMe or Hack The Box, with a profile link.
- Basic scripting in Python or PowerShell for log parsing.
- Familiarity with ISO 27001, NIST CSF, or PCI DSS control language.
Exceptional, and know it?
We would rather have one exceptional person at top pay than two average ones. Make the case.