
Security Operations Analyst – Cyber Defense
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in India, +4 more countries.
• Oversee, assess, and probe security alerts across SIEM, EDR, Microsoft security tools, and cloud environments.
• Evaluate host and network logs from Windows, Linux, databases, applications, web servers, firewalls, and NIDS/HIDS.
• Examine suspicious activities and pinpoint possible root causes.
• Assist in incident response, remediation, and recovery operations.
• Establish suitable escalation routes and collaborate with relevant cybersecurity teams.
• Partner with Incident Response experts to investigate and handle threats.
• Identify areas for enhancing detection quality and minimizing false positives.
• Aid in optimizing security monitoring and fine-tuning whitelists.
• Compile technical reports, summaries, and security findings.
• Maintain SOC documentation, procedures, and content for the knowledge base.
• Contribute to initiatives for process enhancements and operational quality.
• Over 5 years of pertinent IT/cybersecurity experience.
• Practical experience in security alert triage and incident investigation.
• Familiarity with SIEM and EDR platforms.
• Proficient log analysis skills across Windows/Linux and enterprise infrastructure.
• Extensive knowledge of Microsoft Security technologies.
• Experience with Azure, AWS, and/or GCP.
• Proficient in SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, ArcSight, or ELK.
• Experience with at least one EDR solution like Microsoft Defender for Endpoint or CrowdStrike.
• Understanding of email security, network monitoring, and incident response.
• Strong knowledge of Linux, macOS, and Windows.
• Fluent in English with exceptional written and verbal communication abilities.
• Experience in Tier-1/Tier-2 Incident Response.
• AWS security monitoring experience in IaaS, PaaS, or SaaS environments.
• Scripting capabilities in Python, PowerShell, Bash, Ruby, or similar languages.
• Relevant certifications such as SC-200, GCIH, CEH, GCFA, GIAC, CCNA, or MCSE.
• Background in a global SOC or distributed cybersecurity team.
• Remote-first work structure.
• Full-time contract for 6 months, with a possibility for extension.
• Practical exposure to real-world threat detection and incident response.
• Opportunity to engage with a global 24/7 Security Operations Centre.
• Collaboration with security experts across various regions and technical fields.
• Experience with SIEM, EDR, cloud, network, and endpoint security.
• Inclusive and transparent recruitment process.
Talan
Pragmatike
Supply Chimp
Pragmatike
Get handpicked remote jobs straight to your inbox weekly.