Security Operations Analyst – SIEM Operations, Threat Detection

Posted 17 hours ago

This is a fully remote position, open to applicants in Czechia.

📋 Description

• Enhance the capabilities of threat detection and cybersecurity operations within the Cyber Security Operations Center.

• Develop, implement, validate, tune, and maintain security monitoring, analytics, and detection capabilities across SIEM, EDR, cloud, and various other cybersecurity platforms.

• Operate, maintain, optimize, and continuously enhance security monitoring and threat detection services.

• Onboard, integrate, test, and validate security data sources, telemetry feeds, and monitoring capabilities.

• Manage the lifecycle of security content and detection use cases, which includes rule reviews, testing, tuning, and ensuring content quality assurance.

• Collaborate with teams focused on cyber threat intelligence, incident response, and cybersecurity operations.

• Engage in cybersecurity architecture reviews and provide informed recommendations.

• Prepare and maintain metrics, dashboards, KPIs, and service performance reports for cybersecurity operations.

• Assess detection effectiveness, monitoring configurations, operational processes, and service deliverables.

• Analyze operational feedback to minimize false positives and enhance detection quality.

• Contribute to quality assurance, process reviews, control validation, service quality assessments, and corrective measures.

• Maintain CSOC procedures, standards, documentation, knowledge base articles, and operational guidance.

• Prepare and present technical reports, summaries, findings, and recommendations to stakeholders.

• Participate in a rotating on-call schedule and address critical system incidents as necessary.


⛳️ Requirements

• Over 5 years of relevant experience in the information technology sector, including the triage of alerts and support for security incidents.

• Demonstrated experience in administering a SIEM platform, ideally Splunk or Microsoft Sentinel SIEM.

• Proven background with SOC tools such as SIEMs and EDRs.

• Ability to independently conduct technical analyses of security threats and collaborate with the Incident Response team.

• Extensive knowledge of Microsoft Security Tools, including M365, Cloud App Security, Azure, Defender for Endpoints, Azure Security, Azure Sentinel, and XDR.

• In-depth understanding of cloud technologies, including Azure, AWS, and GCP.

• Comprehensive knowledge of SIEM tools like Splunk, QRadar, ArcSight, MS Sentinel, and ELK Stack.

• Familiarity with at least one EDR solution, such as MS Defender for Endpoint or CrowdStrike.

• Understanding of email security, network monitoring, and incident response.

• Knowledge of Linux, Mac, and Windows operating systems.

• Proficiency in English at a C1 level.

• Required participation in a rotating 24/7 on-call schedule, approximately one full week every few months.

• Experience in building SIEM architectures from initial design to implementation, including data ingestion pipelines for various cloud and on-premises log sources (nice to have).

• Proven expertise in monitoring AWS environments (IaaS, SaaS, PaaS) (nice to have).

• Familiarity with at least one general-purpose or shell scripting language, such as Ruby, Bash, PowerShell, or Python (nice to have).

• Desired certifications include MCSE, CCNA, Microsoft Azure SC-200, GCIH, CEH, GCFA, or any GIAC/similar certification.

• Excellent communication skills.

• Experience in customer-facing roles and strong oral communication abilities.

• Capability to write documentation and reports effectively.

• Creativity and the ability to devise innovative solutions.

• Willingness to learn on the job.

• Skills in conflict management and cooperation.


🏝️ Benefits

• Remote work opportunity.

• Full-time freelance contract.

• Opportunities for training and career development.

• Chance to be part of a multicultural team.

• Involvement in international projects.

People also viewed

Pragmatike18 hours ago

Security Operations Analyst – SIEM, Threat Detection

ES flagSpain OnlyFreelanceSecurity Operations
ApplyView job
Supply Chimp20 hours ago

SOC Analyst Level 2

PH flagPhilippines OnlyFull-timeSecurity OperationsPHP 65k – PHP 80k/month
ApplyView job
Pragmatike1 day ago

Security Operations Analyst – Cyber Defense Operations

ES flagSpain, +5 more countriesFull-timeSecurity Operations
ApplyView job
Pragmatike1 day ago

Security Operations Analyst – Cyber Defense

IN flagIndia, +4 more countriesFull-timeSecurity Operations
ApplyView job
Talan1 day ago

Security Operations Analyst – SIEM Operations, Threat Detection

PL flagPoland OnlyFull-timeSecurity Operations
ApplyView job
Talan1 day ago

Senior Cybersecurity Analyst – Cyber Defense Operations

ES flagSpain OnlyFull-timeSecurity Operations
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers