
Senior Security Analyst
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Argentina.
• Oversee and prioritize security alerts originating from SIEM, EDR/XDR, firewall, IDS/IPS, endpoint, identity, email, cloud, and various other client telemetry sources.
• Conduct preliminary investigations to confirm alerts, evaluate scope, assess severity, and identify potential root causes.
• Examine intrusion detection alerts, firewall logs, endpoint activities, system logs, network traffic, and authentication events to detect suspicious or malicious actions.
• Ascertain the success of attacks, document supporting evidence, and inform clients as per established escalation and communication protocols.
• Recognize indicators of compromise, enhance events with threat intelligence, and correlate relevant activities with frameworks such as MITRE ATT&CK when applicable.
• Aid incident response by delivering technical insights, suggested containment measures, and timely updates to clients and internal teams.
• Record investigation processes, timelines, findings, client interactions, and recommendations in case management systems.
• Contribute to detection tuning, minimizing false positives, creating knowledge base articles, developing runbooks, and improving processes.
• Engage in ongoing research regarding emerging threats, vulnerabilities, attacker strategies, and security operations best practices.
• Exceptional interpersonal, organizational, communication, and technical writing abilities.
• Capability to convey technical findings, threat information, and suggested actions clearly to clients and internal stakeholders.
• Aptitude for working independently, adhering to established protocols, prioritizing alerts, and escalating as necessary.
• Proficient understanding of TCP/IP, common network services, and major application layer protocols such as HTTP, SMTP, DNS, and SMB.
• Conceptual knowledge of network and systems architecture, including firewalls, DMZs, intrusion detection systems, web application architecture, endpoint security, and Active Directory.
• Familiarity with prevalent malware types, attacker methodologies, vulnerabilities, and attack vectors such as phishing, brute force attacks, port scanning, SQL injection, credential abuse, and drive-by/redirection attacks.
• Ability to review and analyze logs, alerts, packet captures, or endpoint telemetry to facilitate security investigations.
• Preferred experience of 1 to 3 years in security operations, IT operations, help desk, desktop support, networking, systems administration, or a similar technical role.
• Preferred familiarity with SIEM, EDR/XDR, ticketing, case management, email security, cloud security, or network security tools.
• Hands-on experience with Elastic SIEM, Elasticsearch Query Language (ES|QL), Microsoft Sentinel, and Microsoft Kusto Query Language (KQL).
• Security-related certifications such as CompTIA Security+, CompTIA Network+, Microsoft SC-900, or equivalent experience are preferred.
• Basic scripting or automation experience in Python, PowerShell, Bash, or similar languages.
• Excellent communication skills and the ability to collaborate effectively in a team setting.
• Proficient in advanced English.
• Swiss Medical SMG 30 (primary family group)
• AWS certifications.
• Corporate benefit program with Pedidos Ya!
• Discounts at Unilever, Samsung, BGH, Peña Flor, among others.
• Discounts in educational institutions.
• Internet and connectivity support.
• Compensation for childcare expenses (for children aged 0 to 3 years).
• Competitive salary and benefits package.
• English language support within the company.
• Work from Anywhere: Flexibility to work globally.
• Gifts for special occasions (marriage, graduation, birthdays, etc.).
• Christmas Box.
• Day off for birthdays.
• Ten calendar days of paternity leave.
• An exceptional learning environment for personal and professional development.
Solo Network
Agile Defense
ExtraHop
EMCOR Group, Inc.
Get handpicked remote jobs straight to your inbox weekly.