
Security Operations Analyst
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in India.
• Oversee and prioritize real-time alerts across EDR, firewall, IPS, WAF, and SIEM platforms.
• Assess alert severity and identify true positives under pressure.
• Ensure ongoing 24x7 threat monitoring through rotating shifts, including nights, weekends, and holidays.
• Perform comprehensive incident investigations by connecting EDR, network, and cloud telemetry.
• Identify the root cause, scope, and indicators of compromise for incidents.
• Deliver incident analysis, containment suggestions, and remediation advice to client teams.
• Enhance SIEM correlation rules and detection logic to minimize false positives and address coverage gaps.
• Record investigation results and incident timelines in case management systems.
• Revise SOC playbooks and standard operating procedures.
• Collaborate with GRC engineers and vCISOs to ensure alignment of threat detection with client compliance needs.
• Facilitate investigation handoffs during shift changes.
• Mentor junior analysts on investigative methodologies.
• Work closely with client stakeholders to uphold robust detection coverage.
• A minimum of 3 years of practical experience in monitoring, triaging, and investigating security alerts within a high-paced SOC environment.
• Proficient in correlating data from EDR, firewall, IPS, WAF, and SIEM tools.
• Capable of managing complex investigations from start to finish and making sound escalation decisions with minimal supervision.
• Ability to document findings and convey intricate technical incidents in straightforward language to client stakeholders.
• Willingness to work a 24x7 rotating shift schedule, including nights, weekends, and holidays.
• Possession of recognized security credentials such as CompTIA Security+, CySA+, GCIH, or equivalent qualifications.
• Hands-on experience with EDR tools like CrowdStrike, SentinelOne, and Defender.
• Practical knowledge of SIEM solutions such as Splunk, Microsoft Sentinel, Sumo Logic, and Wazuh.
• Experience in configuring, maintaining, and fine-tuning security platforms beyond routine alert triage.
• Proficient in writing Python or PowerShell scripts and developing SOAR playbooks.
• Previous experience in managed security service provider environments supporting multiple client organizations simultaneously.
• Familiarity with SOC 2, ISO 27001, and HIPAA requirements as they relate to threat detection and incident response.
• Exceptional written and verbal communication skills in English.
• Access to a reliable, high-speed internet connection and a professional home office setup conducive to confidential discussions and uninterrupted shift coverage.
• Openness to local travel for occasional onsite meetings, team events, or business purposes.
• Participation in live video interviews with the camera on and identity verification during the recruitment and onboarding process.
• Successful completion of identity verification and background screening, where legally permissible.
• Clear career progression with mentorship and training opportunities.
• Reimbursement for the successful completion of approved training and certification courses relevant to the current position.
• Competitive base salary with regular performance evaluations linked to merit-based reviews and bonus potential.
• Significant opportunities for career growth.
• Remote-first flexibility to work from anywhere while engaging with a global team, within the assigned shift.
Talan
Pragmatike
Supply Chimp
Pragmatike
Get handpicked remote jobs straight to your inbox weekly.