
Security Operations Analyst – SIEM Operations, Threat Detection
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Spain.
• Enhance the capabilities of threat detection and cybersecurity operations within the Cyber Security Operations Center.
• Design, implement, validate, fine-tune, and sustain security monitoring, analytics, and detection capabilities across SIEM, EDR, cloud, and various other cybersecurity platforms.
• Operate, manage, optimize, and continually enhance security monitoring and threat detection services.
• Onboard, integrate, test, and validate security data sources, telemetry feeds, and monitoring capabilities.
• Oversee security content management, including the lifecycle of detection use cases, rule evaluations, testing, tuning, and assurance of content quality.
• Collaborate with cyber threat intelligence, incident response, and cybersecurity operations teams to convert requirements into effective detection and monitoring capabilities.
• Engage in cybersecurity architecture reviews and provide suggestions to enhance monitoring and detection efficiency.
• Prepare and maintain metrics for cybersecurity operations, dashboards, KPIs, and service performance reports.
• Evaluate and analyze detections, monitoring configurations, operational procedures, and service deliverables to identify areas for improvement.
• Analyze operational feedback to optimize tuning, minimize false positives, and enhance detection quality.
• Contribute to quality assurance, process evaluations, control validations, service quality assessments, and corrective measures.
• Maintain CSOC procedures, standards, documentation, knowledge base articles, and operational guidelines.
• Prepare and deliver technical reports, summaries, findings, and recommendations to both internal and external stakeholders.
• Participate in the mandatory rotating on-call schedule to address critical incidents when necessary.
• Mandatory involvement in a rotating 24/7 on-call shift schedule from Monday to Sunday; approximately one full week every X months based on team size.
• Over 5 years of relevant experience in information technology, including alert triage and security incident support.
• Proven experience managing a SIEM platform, preferably Splunk or Microsoft Sentinel SIEM.
• Demonstrated experience with SOC tools such as SIEMs and EDRs; capable of independently conducting technical analysis of security threats and collaborating with the Incident Response team.
• Extensive knowledge of Microsoft Security Tools, including M365, Cloud App Security, Azure, Defender for Endpoint, Azure Security, Azure Sentinel, and XDR.
• In-depth understanding of cloud technologies such as Azure, AWS, and GCP.
• Profound knowledge of SIEM tools including Splunk, QRadar, ArcSight, MS Sentinel, and ELK Stack.
• Familiarity with at least one EDR solution, such as MS Defender for Endpoint or CrowdStrike.
• Understanding of email security, network monitoring, and incident response.
• Proficiency in Linux, Mac, and Windows.
• C1 level English proficiency.
• Experience in constructing SIEM architectures from the initial design phase to implementation, including data ingestion pipelines for various cloud and on-premises log sources.
• Proven expertise in monitoring AWS environments (IaaS, SaaS, PaaS).
• Knowledge of at least one general-purpose or shell scripting language, such as Ruby, Bash, PowerShell, or Python.
• Preferred certifications include MCSE, CCNA, Microsoft Azure SC-200, GCIH, CEH, GCFA, or any GIAC/similar certification.
• Exceptional communication skills.
• Experience in customer-facing roles and oral communication.
• Ability to produce documentation and reports.
• Creativity and a knack for discovering innovative solutions.
• Eagerness to learn on the job.
• Skills in conflict management and collaboration.
• Remote position.
• Freelance, full-time contract.
• Opportunities for training and career development.
• Chance to be part of a multicultural team and work on international projects.
Talan
Pragmatike
Supply Chimp
Pragmatike
Get handpicked remote jobs straight to your inbox weekly.