Senior Security Operations Analyst
Indexed description
In return for your drive, determination, and curiosity, we’ll provide the resources, mentorship, and opportunities to help you quickly broaden your expertise, grow into a well-rounded professional, and contribute to work that truly makes a difference.
When you join us, you will have:
- Continuous learning: Our learning and apprenticeship culture, backed by structured programs, is all about helping you grow while creating an environment where feedback is clear, actionable, and focused on your development. The real magic happens when you take the input from others to heart and embrace the fast-paced learning experience, owning your journey.
- A voice that matters: From day one, we value your ideas and contributions. You’ll make a tangible impact by offering innovative ideas and practical solutions, all while upholding our unwavering commitment to ethics and integrity. We not only encourage diverse perspectives, but they are critical in driving us toward the best possible outcomes.
- Global community: With colleagues across 65+ countries and over 100 different nationalities, our firm’s diversity fuels creativity and helps us come up with the best solutions. Plus, you’ll have the opportunity to learn from exceptional colleagues with diverse backgrounds and experiences.
- Exceptional benefits: On top of a competitive salary (based on your location, experience, and skills), we provide a comprehensive benefits package to enable holistic well-being for you and your family.
You will investigate and respond to security incidents generated from multiple detection sources, serving as an incident handler for high-impact security events sources, serving as an incident handler for high-impact security events. You will perform endpoint, network, identity, and cloud log analysis to identify malicious activity, determine root cause, communicate to leadership and recommend appropriate containment and remediation actions.
You will conduct incident triage, containment, eradication, recovery, and post-incident documentation in accordance with established response procedures. You will also perform threat hunting activities using endpoint, network, and cloud telemetry to proactively identify suspicious behavior and emerging threats.
You will develop, tune, and optimize security detection use cases, correlation rules, to improve monitoring effectiveness and reduce false positives. You will contribute to the development and enhancement of SOC automation workflows and playbooks to improve operational efficiency. Also, you will contribute to the continuous improvement of SOC processes, detection capabilities, and incident response procedures.
Your Qualifications and Skills
- Industry certifications such as GCIH, GCFA, GCFE, CEH, or equivalent are preferred
- 4+ years of hands-on experience in Security Operations, Cyber Defense, Incident Response, or Threat Detection
- Experience working within a Security Operations Center (SOC) or Cyber Defense team, handling security monitoring and incident response activities
- Strong understanding of security monitoring, incident detection, investigation, and response across enterprise and multi-cloud environments
- Hands-on experience investigating security events across AWS, Microsoft Azure, and Google Cloud Platform (GCP), with familiarity with cloud-native security services and logging
- Solid understanding of the Cyber Kill Chain®, MITRE ATT&CK Framework, modern threat actor tactics, techniques, and procedures (TTPs), and incident response methodologies
- Experience analyzing endpoint, network, authentication, application, and cloud logs using SIEM and XDR platforms
- Strong working knowledge of Microsoft Defender EDR, and Palo Alto Cortex XSIAM
- Experience using EDR/XDR, SIEM, IDS/IPS, email security, identity security, and cloud security tools during investigations
- Working knowledge of Python, PowerShell, or Bash for investigation, automation, or operational efficiency
- Strong analytical and problem-solving skills with the ability to investigate and resolve complex security incidents
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search