
Security Operations Analyst – SIEM Operations, Threat Detection
Posted 17 hours ago

Posted 17 hours ago
This is a fully remote position, open to applicants in Czechia.
• Enhance the capabilities of threat detection and cybersecurity operations within the Cyber Security Operations Center.
• Develop, implement, validate, tune, and maintain security monitoring, analytics, and detection capabilities across SIEM, EDR, cloud, and various other cybersecurity platforms.
• Operate, maintain, optimize, and continuously enhance security monitoring and threat detection services.
• Onboard, integrate, test, and validate security data sources, telemetry feeds, and monitoring capabilities.
• Manage the lifecycle of security content and detection use cases, which includes rule reviews, testing, tuning, and ensuring content quality assurance.
• Collaborate with teams focused on cyber threat intelligence, incident response, and cybersecurity operations.
• Engage in cybersecurity architecture reviews and provide informed recommendations.
• Prepare and maintain metrics, dashboards, KPIs, and service performance reports for cybersecurity operations.
• Assess detection effectiveness, monitoring configurations, operational processes, and service deliverables.
• Analyze operational feedback to minimize false positives and enhance detection quality.
• Contribute to quality assurance, process reviews, control validation, service quality assessments, and corrective measures.
• Maintain CSOC procedures, standards, documentation, knowledge base articles, and operational guidance.
• Prepare and present technical reports, summaries, findings, and recommendations to stakeholders.
• Participate in a rotating on-call schedule and address critical system incidents as necessary.
• Over 5 years of relevant experience in the information technology sector, including the triage of alerts and support for security incidents.
• Demonstrated experience in administering a SIEM platform, ideally Splunk or Microsoft Sentinel SIEM.
• Proven background with SOC tools such as SIEMs and EDRs.
• Ability to independently conduct technical analyses of security threats and collaborate with the Incident Response team.
• Extensive knowledge of Microsoft Security Tools, including M365, Cloud App Security, Azure, Defender for Endpoints, Azure Security, Azure Sentinel, and XDR.
• In-depth understanding of cloud technologies, including Azure, AWS, and GCP.
• Comprehensive knowledge of SIEM tools like Splunk, QRadar, ArcSight, MS Sentinel, and ELK Stack.
• Familiarity with at least one EDR solution, such as MS Defender for Endpoint or CrowdStrike.
• Understanding of email security, network monitoring, and incident response.
• Knowledge of Linux, Mac, and Windows operating systems.
• Proficiency in English at a C1 level.
• Required participation in a rotating 24/7 on-call schedule, approximately one full week every few months.
• Experience in building SIEM architectures from initial design to implementation, including data ingestion pipelines for various cloud and on-premises log sources (nice to have).
• Proven expertise in monitoring AWS environments (IaaS, SaaS, PaaS) (nice to have).
• Familiarity with at least one general-purpose or shell scripting language, such as Ruby, Bash, PowerShell, or Python (nice to have).
• Desired certifications include MCSE, CCNA, Microsoft Azure SC-200, GCIH, CEH, GCFA, or any GIAC/similar certification.
• Excellent communication skills.
• Experience in customer-facing roles and strong oral communication abilities.
• Capability to write documentation and reports effectively.
• Creativity and the ability to devise innovative solutions.
• Willingness to learn on the job.
• Skills in conflict management and cooperation.
• Remote work opportunity.
• Full-time freelance contract.
• Opportunities for training and career development.
• Chance to be part of a multicultural team.
• Involvement in international projects.
Pragmatike
Supply Chimp
Pragmatike
Pragmatike
Get handpicked remote jobs straight to your inbox weekly.