
Security Analyst II
Posted Sep 1

Posted Sep 1
This is a fully remote position, open to applicants in India.
• Serve as a senior member of the Security Operations Center.
• Independently oversee and resolve security incidents from start to finish.
• Lead investigations into incidents and conduct root cause analyses.
• Promote lessons learned and initiatives for continuous improvement.
• Collaborate with global security teams to enhance processes, tools, and operational best practices.
• Analyze intricate security logs, SIEM alerts, and correlated data to identify, evaluate, and address threats.
• Maintain and upgrade security tools.
• Develop and refine SIEM use cases and detection logic based on changing threat intelligence.
• Identify risks, security vulnerabilities, and opportunities to strengthen the organization's security posture.
• Contribute to 24/7 SOC monitoring, detection, and response coverage.
• Mentor junior analysts and cultivate a collaborative, high-performing team culture.
• A minimum of 4 years' experience in Information Security or related cybersecurity positions.
• Practical experience in a Security Operations Center (SOC).
• Significant familiarity with SIEM, endpoint, and network security technologies.
• At least 2 years of experience with cloud environments and cloud-native security tools.
• Experience with SOAR platforms and scripting in Python, PowerShell, Bash, or similar is highly advantageous.
• Working knowledge of Linux systems, including command-line syslog analysis.
• Strong grasp of cloud security principles, such as access control, data protection, threat detection, and compliance monitoring.
• Ability to perform root cause analysis and implement risk mitigation strategies.
• Excellent analytical and problem-solving skills.
• Outstanding communication abilities with both technical and non-technical stakeholders across various time zones.
• High attention to detail, a strong sense of ownership, and a commitment to continuous improvement.
• Ability to remain composed under pressure and manage incidents systematically.
• Experience with Azure Sentinel, QRadar, Splunk, Cisco IDS/IPS, Palo Alto, McAfee Security Suite, Tenable Nessus, ForeScout, and Cisco ISE.
• Familiarity with KQL or SQL is beneficial.
• Operational knowledge of APIs is a plus.
• A Bachelor's degree in Computer Information Systems, Cybersecurity, or a related field, or equivalent experience.
• Certifications considered advantageous include CompTIA Security+ CE, CEH, ECSA, ECIH, CompTIA CySA+, SC-200 or relevant cloud security certifications, Cisco CCNA/CCNP + Security, ITIL Foundation, and Linux+.
• CISSP or CISSP-ISSEP, SSCP, and MCSE certifications are additionally desirable.
• Must be willing to work rotating shifts in a 24x7 operational environment, including night shifts.
• Work schedule aligns with Indian Standard Time (IST).
• Competitive compensation package.
• Comprehensive group benefits for employees and their families.
• Flexibility in work arrangements.
• Time off available as needed.
• Casual work environment.
• Continuous learning opportunities inherent to the role.
Vivo (Telefônica Brasil)
IT Coalition
DraftKings Inc.
Get handpicked remote jobs straight to your inbox weekly.