
SOC Analyst
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Mexico.
• Oversee security alerts generated from SIEM, EDR, and cloud systems.
• Conduct preliminary triage and categorize alerts as either true or false positives.
• Examine suspicious activities across endpoints, identities, and cloud settings.
• Forward confirmed incidents to Tier 2 / Incident Response teams with appropriate context.
• Analyze logs from various sources, including CloudTrail, Azure Activity Logs, OS logs, and other pertinent security data sources.
• Clearly document findings in tickets and investigation reports.
• Adhere to existing playbooks and assist in enhancing detection logic over time.
• Effectively communicate with internal teams and clients regarding alerts, findings, and escalations.
• At least 1 year of experience in SOC / Security Operations.
• Practical experience with EDR tools such as CrowdStrike, SentinelOne, or Microsoft Defender for Endpoint.
• Familiarity with SIEM platforms like Splunk, Microsoft Sentinel, QRadar, or similar.
• Basic understanding of networking concepts, including IP, DNS, HTTP/S, ports, and related topics.
• Fundamental knowledge of Linux and Windows operating systems.
• Capability to analyze logs and detect suspicious activities.
• Proficiency in English, both written and spoken — required.
• Strong verbal communication skills, particularly in client-facing scenarios.
• Experience with cloud environments such as AWS, Azure, or GCP is preferred.
• Knowledge of GCP / Google Cloud Platform is a significant advantage.
• Ability to investigate cloud activities, including IAM, API calls, and resource modifications.
• Understanding of identity-based attacks, such as token abuse and privilege escalation.
• Experience with scripting in Python or Bash.
• Competitive salary and performance-based bonuses.
• Comprehensive health, dental, and vision insurance.
• Opportunities for professional development and training.
• Flexible working hours and remote work options.
• Collaborative and inclusive company culture.
Gcore
UltraViolet Cyber
Get handpicked remote jobs straight to your inbox weekly.