
Security Operations Analyst – Cyber Defense Operations
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Spain, +5 more countries.
• Oversee, prioritize, and investigate security alerts utilizing SIEM, EDR, Microsoft security tools, and various cloud platforms.
• Examine host and network logs from Windows, Linux, databases, applications, web servers, firewalls, and NIDS/HIDS.
• Explore suspicious activities, pinpoint root causes, and decide on suitable remediation or escalation strategies.
• Assist in incident response, remediation, and recovery efforts.
• Collaborate closely with Incident Response and other cybersecurity teams to address security threats.
• Analyze network and security events leveraging TCP/IP, syslog, firewall, and network monitoring data.
• Discover opportunities to enhance detection quality and minimize false positives through tuning and optimization efforts.
• Collect technical details from clients to enhance security monitoring and detection capabilities.
• Create and deliver security reports, summaries, and technical findings.
• Contribute to SOC procedures, documentation, knowledge bases, and quality-control initiatives.
• Assess operational feedback and implement corrective measures to consistently enhance service quality.
• A minimum of 5 years of relevant experience in IT/cybersecurity, including security alert triage and incident support.
• Practical experience in a SOC environment.
• Strong familiarity with SIEM and EDR platforms.
• Advanced log analysis proficiency across Windows/Linux, databases, applications, and infrastructure.
• In-depth knowledge of Microsoft Security technologies, including Microsoft Sentinel and Defender.
• Experience in cloud security across Azure, AWS, and/or GCP.
• Proficiency with SIEM platforms such as Splunk, QRadar, ArcSight, Microsoft Sentinel, or ELK.
• Experience with at least one EDR solution like Microsoft Defender for Endpoint or CrowdStrike.
• Understanding of email security, network monitoring, and incident response processes.
• Strong knowledge of Linux, macOS, and Windows operating systems.
• Fluent English with exceptional written and verbal communication skills.
• Previous experience on an Incident Response team handling Tier-1/Tier-2 incident triage.
• AWS security monitoring experience within IaaS, PaaS, or SaaS environments.
• Scripting skills in Python, PowerShell, Bash, Ruby, or similar languages.
• Relevant certifications such as Microsoft SC-200, GCIH, CEH, GCFA, GIAC, CCNA, or MCSE.
• Customer-facing cybersecurity experience.
• Engage within a global 24/7 cybersecurity operation safeguarding international organizations.
• Gain exposure to expansive cloud, SIEM, EDR, network, and endpoint security environments.
• Collaborate with cybersecurity experts from various regions and disciplines.
• Directly participate in real-world threat detection and incident response efforts.
• Accumulate experience across a diverse enterprise security technology stack.
• Opportunity for contract extension following a 6-month period.
Talan
Pragmatike
Supply Chimp
Pragmatike
Get handpicked remote jobs straight to your inbox weekly.