Security Operations Analyst – Cyber Defense

Posted 1 day ago

This is a fully remote position, open to applicants in India, +4 more countries.

📋 Description

• Oversee, assess, and probe security alerts across SIEM, EDR, Microsoft security tools, and cloud environments.

• Evaluate host and network logs from Windows, Linux, databases, applications, web servers, firewalls, and NIDS/HIDS.

• Examine suspicious activities and pinpoint possible root causes.

• Assist in incident response, remediation, and recovery operations.

• Establish suitable escalation routes and collaborate with relevant cybersecurity teams.

• Partner with Incident Response experts to investigate and handle threats.

• Identify areas for enhancing detection quality and minimizing false positives.

• Aid in optimizing security monitoring and fine-tuning whitelists.

• Compile technical reports, summaries, and security findings.

• Maintain SOC documentation, procedures, and content for the knowledge base.

• Contribute to initiatives for process enhancements and operational quality.


⛳️ Requirements

• Over 5 years of pertinent IT/cybersecurity experience.

• Practical experience in security alert triage and incident investigation.

• Familiarity with SIEM and EDR platforms.

• Proficient log analysis skills across Windows/Linux and enterprise infrastructure.

• Extensive knowledge of Microsoft Security technologies.

• Experience with Azure, AWS, and/or GCP.

• Proficient in SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, ArcSight, or ELK.

• Experience with at least one EDR solution like Microsoft Defender for Endpoint or CrowdStrike.

• Understanding of email security, network monitoring, and incident response.

• Strong knowledge of Linux, macOS, and Windows.

• Fluent in English with exceptional written and verbal communication abilities.

• Experience in Tier-1/Tier-2 Incident Response.

• AWS security monitoring experience in IaaS, PaaS, or SaaS environments.

• Scripting capabilities in Python, PowerShell, Bash, Ruby, or similar languages.

• Relevant certifications such as SC-200, GCIH, CEH, GCFA, GIAC, CCNA, or MCSE.

• Background in a global SOC or distributed cybersecurity team.


🏝️ Benefits

• Remote-first work structure.

• Full-time contract for 6 months, with a possibility for extension.

• Practical exposure to real-world threat detection and incident response.

• Opportunity to engage with a global 24/7 Security Operations Centre.

• Collaboration with security experts across various regions and technical fields.

• Experience with SIEM, EDR, cloud, network, and endpoint security.

• Inclusive and transparent recruitment process.

People also viewed

Talan17 hours ago

Security Operations Analyst – SIEM Operations, Threat Detection

CZ flagCzechia OnlyFull-timeSecurity Operations
ApplyView job
Pragmatike18 hours ago

Security Operations Analyst – SIEM, Threat Detection

ES flagSpain OnlyFreelanceSecurity Operations
ApplyView job
Supply Chimp20 hours ago

SOC Analyst Level 2

PH flagPhilippines OnlyFull-timeSecurity OperationsPHP 65k – PHP 80k/month
ApplyView job
Pragmatike1 day ago

Security Operations Analyst – Cyber Defense Operations

ES flagSpain, +5 more countriesFull-timeSecurity Operations
ApplyView job
Talan1 day ago

Security Operations Analyst – SIEM Operations, Threat Detection

PL flagPoland OnlyFull-timeSecurity Operations
ApplyView job
Talan1 day ago

Senior Cybersecurity Analyst – Cyber Defense Operations

ES flagSpain OnlyFull-timeSecurity Operations
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers