
SIEM Analyst
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Argentina.
• Gather, normalize, analyze, and utilize security logs from diverse sources within the organization.
• Design, implement, and sustain log collection pipelines for security, infrastructure, cloud, and application systems.
• Ensure logs are correctly ingested, parsed, normalized, and retained across SIEM platforms like FortiAnalyzer, Splunk, and CrowdStrike.
• Uphold data quality and consistency across various log sources.
• Create, develop, and manage dashboards and visualizations that reflect security posture, threats, and operational metrics.
• Formulate, fine-tune, and maintain correlation rules and alerts based on attack patterns, indicators of compromise, behavioral anomalies, and tailored detection use cases.
• Examine logs to detect suspicious, anomalous, or irregular behavior.
• Actively hunt for threats using advanced log searches and pattern analysis.
• Assist in incident response and forensic investigations by analyzing historical logs, reconstructing attack timelines, and identifying entry points, lateral movements, and attacker activities.
• Collaborate with SOC Analysts, Dev Security, IAM, Threat Hunting, and other security professionals during incident investigation and response.
• Confirm alerts and detections to minimize false positives and enhance detection quality.
• Document and monitor detections, investigations, and findings using Jira tickets.
• Develop and refresh procedures for log management, detection, and investigation.
• Generate operational, technical, and management reports derived from SIEM data.
• Participate in ongoing training and professional development.
• Share knowledge and expertise with the team.
• Comply with organizational policies and maintain organized, traceable work through Jira.
• Education in computer science, telecommunications, cybersecurity, or other related fields.
• Minimum of 3 years of experience in SIEM operations, log analysis, or security monitoring roles.
• Practical experience in collecting and managing logs from various sources, including endpoints, network devices, servers, cloud services, applications, and authentication systems.
• At least 2 years of experience working with Splunk, including operating and configuring rules and settings.
• At least 2 years of experience with CrowdStrike.
• Familiarity with SIEM and log platforms such as FortiAnalyzer, New Relic, ManageEngine AD Audit, Axonius, or similar tools.
• Experience in creating dashboards, visualizations, and reports based on log data.
• Proficient in defining and fine-tuning alerts and correlation rules.
• Knowledge of SIEM scripting or query languages such as SPL, KQL, and SQL-like queries.
• Understanding of YARA rules and regular expressions (regex).
• Knowledge of security tools that generate logs, including firewalls, EDR, IAM, cloud platforms, and application security tools.
• Strong analytical capabilities for recognizing patterns and anomalies in extensive datasets.
• Experience in supporting incident response and forensic investigations through log analysis.
• Ability to work independently as well as collaboratively within the Information Security Team with minimal supervision.
• Willingness to learn and continuously enhance detection capabilities.
• Excellent documentation and reporting skills.
• Solid understanding of networking, operating systems, authentication processes, and cybersecurity.
• Ability to comprehend how logs reflect system and user behavior across various platforms.
• Any cybersecurity certification is a plus.
• Experience with log normalization standards and detection methodologies is advantageous.
• Familiarity with MITRE ATT&CK and threat detection frameworks is beneficial.
• Experience engaging in threat hunting activities is a bonus.
• Understanding of forensic analysis concepts and incident response workflows is beneficial.
• Must reside in the Americas, preferably in South or Central America.
• 22 days of annual leave.
• 10 days of national holidays.
• Health insurance options.
• Access to e-learning platforms.
• Opportunity for on-site English classes in select countries.
• Professional development opportunities.
• Options for remote or on-site work.
Republic Services
Curtiss-Wright Corporation
Get handpicked remote jobs straight to your inbox weekly.