
Security Operations Analyst
Posted Aug 24

Posted Aug 24
This is a fully remote position, open to applicants in Brazil, +4 more countries.
• Take ownership of escalated security incidents from initial triage to resolution, containment, or escalation to senior staff during weekday evenings and overnight hours.
• Conduct investigations into complex activities utilizing SIEM, EDR, identity, network, and email security tools.
• Differentiate between false positives and actual security incidents.
• Ensure comprehensive and clear documentation of security events.
• Facilitate structured shift transitions with the daytime Security Operations team.
• Analyze alert trends and enhance detection rules to minimize false positives.
• Optimize detection mechanisms.
• Identify opportunities for security automation and enhance SOAR playbooks.
• Drive initiatives within the SecOps backlog, including threat-hunting hypotheses and upgrades to operational capabilities.
• Expand the daytime Security team's coverage towards a 24x7 operational model.
• A minimum of 5 years of pertinent experience in cybersecurity and Security Operations (SOC) settings.
• In-depth knowledge in SIEM investigations, comprehensive incident response, and triage of complex security incidents.
• Strong expertise in Endpoint Detection and Response (EDR) platforms and fundamental endpoint security principles.
• Exceptional troubleshooting abilities and capacity to work independently.
• Capability to make informed containment decisions with minimal supervision.
• A proactive approach aimed at identifying operational inefficiencies and enhancing SecOps processes.
• Proficient in spoken and written English.
• Hands-on experience with Splunk, Splunk ES, Splunk SOAR, SentinelOne, CrowdStrike, Microsoft Defender, or Google SecOps.
• Background in detection engineering, rule tuning, threat hunting, and the application of the MITRE ATT&CK framework.
• Proficiency in Python or scripting languages, along with practical SOAR integration experience.
• Familiarity with AWS/cloud security environments and vulnerability management tools like Tenable.
• Remote working opportunities.
• Direct contract with Inallmedia.com.
• Global, distributed team environment.
• Exposure to international clients and cybersecurity projects.
Gcore
UltraViolet Cyber
Get handpicked remote jobs straight to your inbox weekly.