
Security Operations Analyst – SIEM Operations, Threat Detection
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Poland.
• Assist in the development, implementation, validation, tuning, and maintenance of security monitoring, analytics, and detection capabilities across SIEM, EDR, cloud, and other cybersecurity platforms.
• Aid in the operation, maintenance, optimization, and ongoing enhancement of security monitoring and threat detection services.
• Engage in the onboarding, integration, testing, and validation of security data sources, telemetry feeds, and monitoring capabilities.
• Support security content management, including use case lifecycle management, rule evaluations, testing, tuning, and content quality assurance.
• Collaborate with cyber threat intelligence, incident response, and cybersecurity operations teams to convert requirements into detection and monitoring capabilities.
• Take part in cybersecurity architecture reviews and offer recommendations to enhance security monitoring and detection effectiveness.
• Create and sustain cybersecurity operations metrics, dashboards, KPIs, and service performance reports.
• Evaluate detections, monitoring configurations, operational processes, and service deliverables, identifying areas for improvement.
• Analyze operational feedback to facilitate tuning, optimization, false-positive reduction, and enhanced detection quality.
• Engage in quality assurance activities, process reviews, control validations, service quality assessments, and corrective measures.
• Assist in the development, review, and maintenance of CSOC procedures, standards, documentation, knowledge base articles, and operational guidance.
• Prepare and present technical reports, summaries, findings, and recommendations to both internal and external stakeholders.
• Participate in a rotating on-call schedule to address critical system incidents as necessary.
• Over 5 years of relevant experience in the information technology sector, including alert triage and support for security incidents.
• Demonstrated experience in administering a SIEM platform, preferably Splunk or Microsoft Sentinel SIEM.
• Proven familiarity with SOC tools such as SIEMs and EDRs.
• Capability to independently conduct technical analyses of security threats and collaborate with the Incident Response team.
• Extensive knowledge of Microsoft Security Tools, including M365, Cloud App Security, Azure, Defender for Endpoints, Azure Security, Azure Sentinel, and XDR.
• In-depth understanding of cloud technologies, including Azure, AWS, and GCP.
• Strong knowledge of SIEM tools such as Splunk, QRadar, ArcSight, Microsoft Sentinel, and ELK Stack.
• Familiarity with at least one EDR solution, such as Microsoft Defender for Endpoint or CrowdStrike.
• Understanding of email security, network monitoring, and incident response.
• Proficiency in Linux, Mac, and Windows environments.
• C1 English proficiency.
• Required participation in a rotating 24/7 on-call schedule, approximately one full week every X months.
• Experience in building SIEM architectures from initial design to implementation (preferred).
• Proven knowledge of monitoring AWS environments (IaaS, SaaS, PaaS) (preferred).
• Familiarity with at least one general-purpose or shell scripting language, such as Ruby, Bash, PowerShell, or Python (preferred).
• Desired certifications: MCSE, CCNA, Microsoft Azure SC-200, GCIH, CEH, GCFA, or any GIAC/similar certification.
• Exceptional communication abilities.
• Experience in customer-facing roles and strong oral communication skills.
• Proficient in writing documentation and reports.
• Creativity and the ability to devise innovative solutions.
• Willingness to learn and grow on the job.
• Skills in conflict management and cooperation.
• Remote position.
• Freelance, full-time contract.
• Opportunities for training and career development.
• Chance to be part of a multicultural team.
• Work on international projects.
Talan
Pragmatike
Supply Chimp
Pragmatike
Get handpicked remote jobs straight to your inbox weekly.