Security Operations Analyst – SIEM Operations, Threat Detection

Posted 1 day ago

This is a fully remote position, open to applicants in Poland.

📋 Description

• Assist in the development, implementation, validation, tuning, and maintenance of security monitoring, analytics, and detection capabilities across SIEM, EDR, cloud, and other cybersecurity platforms.

• Aid in the operation, maintenance, optimization, and ongoing enhancement of security monitoring and threat detection services.

• Engage in the onboarding, integration, testing, and validation of security data sources, telemetry feeds, and monitoring capabilities.

• Support security content management, including use case lifecycle management, rule evaluations, testing, tuning, and content quality assurance.

• Collaborate with cyber threat intelligence, incident response, and cybersecurity operations teams to convert requirements into detection and monitoring capabilities.

• Take part in cybersecurity architecture reviews and offer recommendations to enhance security monitoring and detection effectiveness.

• Create and sustain cybersecurity operations metrics, dashboards, KPIs, and service performance reports.

• Evaluate detections, monitoring configurations, operational processes, and service deliverables, identifying areas for improvement.

• Analyze operational feedback to facilitate tuning, optimization, false-positive reduction, and enhanced detection quality.

• Engage in quality assurance activities, process reviews, control validations, service quality assessments, and corrective measures.

• Assist in the development, review, and maintenance of CSOC procedures, standards, documentation, knowledge base articles, and operational guidance.

• Prepare and present technical reports, summaries, findings, and recommendations to both internal and external stakeholders.

• Participate in a rotating on-call schedule to address critical system incidents as necessary.


⛳️ Requirements

• Over 5 years of relevant experience in the information technology sector, including alert triage and support for security incidents.

• Demonstrated experience in administering a SIEM platform, preferably Splunk or Microsoft Sentinel SIEM.

• Proven familiarity with SOC tools such as SIEMs and EDRs.

• Capability to independently conduct technical analyses of security threats and collaborate with the Incident Response team.

• Extensive knowledge of Microsoft Security Tools, including M365, Cloud App Security, Azure, Defender for Endpoints, Azure Security, Azure Sentinel, and XDR.

• In-depth understanding of cloud technologies, including Azure, AWS, and GCP.

• Strong knowledge of SIEM tools such as Splunk, QRadar, ArcSight, Microsoft Sentinel, and ELK Stack.

• Familiarity with at least one EDR solution, such as Microsoft Defender for Endpoint or CrowdStrike.

• Understanding of email security, network monitoring, and incident response.

• Proficiency in Linux, Mac, and Windows environments.

• C1 English proficiency.

• Required participation in a rotating 24/7 on-call schedule, approximately one full week every X months.

• Experience in building SIEM architectures from initial design to implementation (preferred).

• Proven knowledge of monitoring AWS environments (IaaS, SaaS, PaaS) (preferred).

• Familiarity with at least one general-purpose or shell scripting language, such as Ruby, Bash, PowerShell, or Python (preferred).

• Desired certifications: MCSE, CCNA, Microsoft Azure SC-200, GCIH, CEH, GCFA, or any GIAC/similar certification.

• Exceptional communication abilities.

• Experience in customer-facing roles and strong oral communication skills.

• Proficient in writing documentation and reports.

• Creativity and the ability to devise innovative solutions.

• Willingness to learn and grow on the job.

• Skills in conflict management and cooperation.


🏝️ Benefits

• Remote position.

• Freelance, full-time contract.

• Opportunities for training and career development.

• Chance to be part of a multicultural team.

• Work on international projects.

People also viewed

Talan17 hours ago

Security Operations Analyst – SIEM Operations, Threat Detection

CZ flagCzechia OnlyFull-timeSecurity Operations
ApplyView job
Pragmatike18 hours ago

Security Operations Analyst – SIEM, Threat Detection

ES flagSpain OnlyFreelanceSecurity Operations
ApplyView job
Supply Chimp20 hours ago

SOC Analyst Level 2

PH flagPhilippines OnlyFull-timeSecurity OperationsPHP 65k – PHP 80k/month
ApplyView job
Pragmatike1 day ago

Security Operations Analyst – Cyber Defense Operations

ES flagSpain, +5 more countriesFull-timeSecurity Operations
ApplyView job
Pragmatike1 day ago

Security Operations Analyst – Cyber Defense

IN flagIndia, +4 more countriesFull-timeSecurity Operations
ApplyView job
Talan1 day ago

Senior Cybersecurity Analyst – Cyber Defense Operations

ES flagSpain OnlyFull-timeSecurity Operations
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers