
Security Operations Analyst – SIEM, Threat Detection
Posted 18 hours ago

Posted 18 hours ago
This is a fully remote position, open to applicants in Spain.
• Design, implement, validate, fine-tune, and sustain security monitoring and detection capabilities.
• Manage and optimize SIEM platforms across various customer environments.
• Oversee the lifecycle of security detection rules and use cases.
• Onboard, integrate, test, and verify new security data sources and telemetry feeds.
• Evaluate and enhance detection logic, security content, and monitoring configurations.
• Partner with Threat Intelligence and Incident Response teams to convert threats into actionable detection capabilities.
• Assist with cybersecurity architecture assessments and offer suggestions to enhance security monitoring.
• Develop and maintain security metrics, dashboards, KPIs, and service-performance reports.
• Assess detection effectiveness and pinpoint opportunities to minimize false positives.
• Contribute to quality assurance, process evaluations, control validation, and corrective measures.
• Uphold SOC procedures, standards, documentation, knowledge bases, and operational guidance.
• Compile technical reports, findings, and recommendations for both internal and external stakeholders.
• Over 5 years of pertinent IT/cybersecurity experience.
• Practical experience administering a SIEM platform, preferably Splunk or Microsoft Sentinel.
• Extensive experience with SIEM/EDR environments and technical security analysis.
• In-depth knowledge of Microsoft Security technologies.
• Strong understanding of cloud security in Azure, AWS, and/or GCP.
• Familiarity with Splunk, QRadar, ArcSight, Microsoft Sentinel, or ELK.
• Experience with at least one EDR platform such as Microsoft Defender for Endpoint or CrowdStrike.
• Knowledge of email security, network monitoring, and incident response.
• Proficient in Linux, macOS, and Windows systems.
• Proficient in English with exceptional written and verbal communication abilities.
• Experience in designing SIEM architecture from concept through implementation.
• Experience creating data-ingestion pipelines for a variety of cloud and on-premise log sources.
• Experience in AWS security monitoring.
• Scripting skills in Python, PowerShell, Bash, Ruby, or similar languages.
• Relevant security certifications such as SC-200, GCIH, CEH, GCFA, GIAC, CCNA, or MCSE.
• Experience working across multiple customer environments.
• Full-time contract lasting 6 months, with the possibility of extension.
• Exposure to extensive SIEM, EDR, cloud, and threat-detection environments.
• Direct collaboration with Threat Intelligence, Incident Response, and Cybersecurity Operations teams.
• Engage in cybersecurity services that support numerous international organizations.
• Fair, transparent, and inclusive recruitment process.
Talan
Supply Chimp
Pragmatike
Pragmatike
Get handpicked remote jobs straight to your inbox weekly.