
Senior Security Analyst
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Bulgaria.
• Oversee security investigations across endpoint devices, identity systems, cloud platforms, and production workloads, encompassing triage, root-cause analysis, containment, and eradication.
• Serve as the incident commander for the region, synchronizing efforts among IT, Engineering, Legal, HR, and various other teams.
• Explore cases that lack established playbooks by determining the necessary data to gather, developing analytical tools, and documenting insights for future reference.
• Compose and conduct peer reviews of case summaries, incident reports, and timelines.
• Proactively search for emerging threats, including AI-driven intrusions and supply-chain compromises.
• Translate threat-hunting discoveries into telemetry, detections, and automation to enhance alert quality and minimize manual intervention.
• Lead post-incident fortification efforts in collaboration with Security Engineering.
• Provide mentorship to analysts through case reviews, escalation assistance, and knowledge sharing.
• A minimum of 6 years in the cybersecurity field, with at least 4 years dedicated to incident response, forensics, threat intelligence, or threat hunting.
• Proven experience managing significant incidents with minimal supervision, under pressure and with incomplete information.
• Skilled in briefing leadership and drafting post-incident reports tailored for engineers and executives.
• Extensive knowledge of current attacker behaviors, including insider threats.
• Familiarity with MITRE ATT&CK, the Diamond Model, and the kill chain framework.
• Practical experience with SIEM, EDR/NDR, and CSPM tools.
• Monitoring experience in endpoint, identity, SaaS, or CI/CD environments.
• Incident investigation experience in at least one major cloud environment, such as AWS, Azure, or GCP.
• Proficient scripting skills in Python, PowerShell, or a similar programming language.
• Experience with YARA-L, Sigma, KQL, SPL, or comparable investigation queries and detection methods.
• May need to obtain a gaming license issued by the relevant state agency as a condition of employment.
• Assistance throughout the gaming license application process if applicable to the position.
Vivo (Telefônica Brasil)
IT Coalition
Get handpicked remote jobs straight to your inbox weekly.