Security Operations Analyst

Posted Aug 24

This is a fully remote position, open to applicants in Brazil, +4 more countries.

📋 Description

• Take ownership of escalated security incidents from initial triage to resolution, containment, or escalation to senior staff during weekday evenings and overnight hours.

• Conduct investigations into complex activities utilizing SIEM, EDR, identity, network, and email security tools.

• Differentiate between false positives and actual security incidents.

• Ensure comprehensive and clear documentation of security events.

• Facilitate structured shift transitions with the daytime Security Operations team.

• Analyze alert trends and enhance detection rules to minimize false positives.

• Optimize detection mechanisms.

• Identify opportunities for security automation and enhance SOAR playbooks.

• Drive initiatives within the SecOps backlog, including threat-hunting hypotheses and upgrades to operational capabilities.

• Expand the daytime Security team's coverage towards a 24x7 operational model.


⛳️ Requirements

• A minimum of 5 years of pertinent experience in cybersecurity and Security Operations (SOC) settings.

• In-depth knowledge in SIEM investigations, comprehensive incident response, and triage of complex security incidents.

• Strong expertise in Endpoint Detection and Response (EDR) platforms and fundamental endpoint security principles.

• Exceptional troubleshooting abilities and capacity to work independently.

• Capability to make informed containment decisions with minimal supervision.

• A proactive approach aimed at identifying operational inefficiencies and enhancing SecOps processes.

• Proficient in spoken and written English.

• Hands-on experience with Splunk, Splunk ES, Splunk SOAR, SentinelOne, CrowdStrike, Microsoft Defender, or Google SecOps.

• Background in detection engineering, rule tuning, threat hunting, and the application of the MITRE ATT&CK framework.

• Proficiency in Python or scripting languages, along with practical SOAR integration experience.

• Familiarity with AWS/cloud security environments and vulnerability management tools like Tenable.


🏝️ Benefits

• Remote working opportunities.

• Direct contract with Inallmedia.com.

• Global, distributed team environment.

• Exposure to international clients and cybersecurity projects.

People also viewed

Gcore22 hours ago

SOC Analyst – WAAP

PL flagPoland, +1 more countryFull-timeSecurity Operations
ApplyView job
UltraViolet Cyber1 day ago

Senior SOC Analyst – MDR

US flagUnited States OnlyFull-timeSecurity Operations
ApplyView job
Commit1 day ago

SOC Analyst

MX flagMexico OnlyFull-timeSecurity Operations
ApplyView job
Commit1 day ago

SOC Analyst

MX flagMexico OnlyFull-timeSecurity Operations
ApplyView job
Commit2 days ago

SOC Analyst

PH flagPhilippines OnlyFull-timeSecurity Operations
ApplyView job
bridge3512 days ago

Security Operations Engineer

EuropeFull-timeSecurity Operations
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers