Security Operations Analyst – SIEM Operations, Threat Detection

Posted 1 day ago

This is a fully remote position, open to applicants in Spain.

📋 Description

• Enhance the capabilities of threat detection and cybersecurity operations within the Cyber Security Operations Center.

• Design, implement, validate, fine-tune, and sustain security monitoring, analytics, and detection capabilities across SIEM, EDR, cloud, and various other cybersecurity platforms.

• Operate, manage, optimize, and continually enhance security monitoring and threat detection services.

• Onboard, integrate, test, and validate security data sources, telemetry feeds, and monitoring capabilities.

• Oversee security content management, including the lifecycle of detection use cases, rule evaluations, testing, tuning, and assurance of content quality.

• Collaborate with cyber threat intelligence, incident response, and cybersecurity operations teams to convert requirements into effective detection and monitoring capabilities.

• Engage in cybersecurity architecture reviews and provide suggestions to enhance monitoring and detection efficiency.

• Prepare and maintain metrics for cybersecurity operations, dashboards, KPIs, and service performance reports.

• Evaluate and analyze detections, monitoring configurations, operational procedures, and service deliverables to identify areas for improvement.

• Analyze operational feedback to optimize tuning, minimize false positives, and enhance detection quality.

• Contribute to quality assurance, process evaluations, control validations, service quality assessments, and corrective measures.

• Maintain CSOC procedures, standards, documentation, knowledge base articles, and operational guidelines.

• Prepare and deliver technical reports, summaries, findings, and recommendations to both internal and external stakeholders.

• Participate in the mandatory rotating on-call schedule to address critical incidents when necessary.


⛳️ Requirements

• Mandatory involvement in a rotating 24/7 on-call shift schedule from Monday to Sunday; approximately one full week every X months based on team size.

• Over 5 years of relevant experience in information technology, including alert triage and security incident support.

• Proven experience managing a SIEM platform, preferably Splunk or Microsoft Sentinel SIEM.

• Demonstrated experience with SOC tools such as SIEMs and EDRs; capable of independently conducting technical analysis of security threats and collaborating with the Incident Response team.

• Extensive knowledge of Microsoft Security Tools, including M365, Cloud App Security, Azure, Defender for Endpoint, Azure Security, Azure Sentinel, and XDR.

• In-depth understanding of cloud technologies such as Azure, AWS, and GCP.

• Profound knowledge of SIEM tools including Splunk, QRadar, ArcSight, MS Sentinel, and ELK Stack.

• Familiarity with at least one EDR solution, such as MS Defender for Endpoint or CrowdStrike.

• Understanding of email security, network monitoring, and incident response.

• Proficiency in Linux, Mac, and Windows.

• C1 level English proficiency.

• Experience in constructing SIEM architectures from the initial design phase to implementation, including data ingestion pipelines for various cloud and on-premises log sources.

• Proven expertise in monitoring AWS environments (IaaS, SaaS, PaaS).

• Knowledge of at least one general-purpose or shell scripting language, such as Ruby, Bash, PowerShell, or Python.

• Preferred certifications include MCSE, CCNA, Microsoft Azure SC-200, GCIH, CEH, GCFA, or any GIAC/similar certification.

• Exceptional communication skills.

• Experience in customer-facing roles and oral communication.

• Ability to produce documentation and reports.

• Creativity and a knack for discovering innovative solutions.

• Eagerness to learn on the job.

• Skills in conflict management and collaboration.


🏝️ Benefits

• Remote position.

• Freelance, full-time contract.

• Opportunities for training and career development.

• Chance to be part of a multicultural team and work on international projects.

People also viewed

Talan1 day ago

Security Operations Analyst – SIEM Operations, Threat Detection

CZ flagCzechia OnlyFull-timeSecurity Operations
ApplyView job
Pragmatike1 day ago

Security Operations Analyst – SIEM, Threat Detection

ES flagSpain OnlyFreelanceSecurity Operations
ApplyView job
Supply Chimp1 day ago

SOC Analyst Level 2

PH flagPhilippines OnlyFull-timeSecurity OperationsPHP 65k – PHP 80k/month
ApplyView job
Pragmatike1 day ago

Security Operations Analyst – Cyber Defense Operations

ES flagSpain, +5 more countriesFull-timeSecurity Operations
ApplyView job
Pragmatike1 day ago

Security Operations Analyst – Cyber Defense

IN flagIndia, +4 more countriesFull-timeSecurity Operations
ApplyView job
Talan1 day ago

Security Operations Analyst – SIEM Operations, Threat Detection

PL flagPoland OnlyFull-timeSecurity Operations
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers