
Cyber Security Analyst
Posted Sep 8

Posted Sep 8
This is a fully remote position, open to applicants in Romania.
• Deliver client-facing support for 24/7 managed security services.
• Follow and enhance operational processes and frameworks.
• Work designated shifts and provide coverage for alternate shifts as required.
• Analyze, escalate, and assist in the remediation of critical information security incidents.
• Integrate, deploy, onboard, and manage endpoint defense and attack surface management for clients.
• Monitor alerts in real-time and assess security event data from network and endpoint environments, peer analysts, customer platforms, and other sources.
• Provide incident response support and remediation advice to clients.
• Review and refine procedures for cyber threat intelligence, monitoring, incident response, attack surface reduction, and automation actions.
• Develop security orchestration, automation, and response playbooks using security operations tools and scripting languages.
• Create, maintain, and oversee automated playbooks for prevalent information security threats and client-specific environments.
• Identify enhancements within Security Operations Center and Cyber Incident Response procedures.
• Integrate new security platform functionalities with existing systems and automated processes.
• Produce documented code, scripts, processes, and service documentation.
• Conduct health checks and optimization activities on client security technologies and systems.
• Assess information security risks and facilitate the remediation of vulnerabilities and security risks across the enterprise.
• A minimum of 4 years of IT experience.
• At least 3 years of experience in Cyber Security.
• Advanced experience with operating systems in at least two of Microsoft, MacOS, and Linux.
• General knowledge of network security and troubleshooting.
• Foundational scripting skills in PowerShell, Python, or Bash are preferred.
• Comprehensive understanding of TCP/IP, UDP, DNS, FTP, SSH, SSL/TLS, and HTTP protocols.
• Familiarity with network analysis and network/security applications.
• Strong knowledge of common malware threats and attack methodologies.
• Expertise in malware and threat analysis.
• Experience in incident management.
• Ability to work under general to minimal supervision.
• More than 3 years of experience with endpoint security tools preferred, including Trellix ePO, Trellix ENS, Trellix EDR, Trellix HX, CrowdStrike, Microsoft Defender, Microsoft ATP, or SentinelOne.
• Over 3 years of managing security endpoints preferred.
• More than 3 years of experience with SIEM management and tuning preferred, including LogScale/Humio, Splunk, Trellix Helix, Trellix ESM, Azure Sentinel, Elastic SIEM, Chronical, or Devo.
• Experience with Windows patch management tools is advantageous.
• Experience in creating detection rules in one or more SIEM technologies is preferred.
• Certifications such as CEH, CRISC, CISA, CGEIT, CISSP, CIPP, GMON, GHIA, or GCIH are beneficial.
• Excellent understanding of security methodologies, including the Cyber Kill Chain, Diamond Models, and MITRE ATT&CK framework.
• A Bachelor's Degree in Math, Computer Science, or Engineering is preferred.
• Role in managed cyber security services.
• Coverage for 24/7 managed security services.
• Opportunity for growth in an innovative environment.
Vision Cybersecurity
Stefanini LATAM
Bancorbrás
Kemper
Get handpicked remote jobs straight to your inbox weekly.