1 месяц назад
SOC Tier 3 Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
SOC Tier 3 Analyst (Cybersecurity): Analyzing escalated security events, investigating threats, and supporting incident response across SIEM, network, endpoint, and OT environments with an accent on threat detection, forensic analysis, and security-event correlation. Focus on proactive threat hunting, IOC ingestion, PCAP and NetFlow analysis, developing SOC runbooks, and improving incident-handling processes.
Location: Santiago, Chile; in-person collaboration is prioritized
Company
delivers mission-critical IT services across security, cloud, analytics, engineering, applications, and modern workplace environments.
What you will do
- Analyze escalated cybersecurity events from Tier 1 and Tier 2 analysts, distinguish benign activity, and escalate confirmed incidents to the Incident Response Lead.
- Correlate logs, alerts, and event data across network devices and enterprise applications to identify incidents and recommend remediation.
- Perform proactive threat hunting and analyze network traffic, NetFlow, packet captures, system data, and forensic artifacts.
- Identify and ingest indicators of compromise into network security tools and support enterprise-wide incident resolution.
- Develop and quality-check technical advisories, SOC procedures, standard operating procedures, and analyst runbooks.
- Analyze trends, report recurring issues, resolve security violations, and propose improvements to alerting and incident handling.
Requirements
- English and Spanish proficiency required for communication with global stakeholders, vendors, and executive leadership.
- At least 3–5 years of operational experience as a cybersecurity analyst or engineer handling incidents and response in critical environments.
- Hands-on experience with SIEM, IDS/IPS, firewalls, NAC, DLP, DAM, endpoint protection, vulnerability scanning, and content-filtering technologies.
- Strong knowledge of TCP/IP networking, firewalls, proxies, intrusion detection, packet analysis, and common operating-system forensic techniques.
- Command-line scripting skills with Python, PowerShell, or Bash, including the ability to create searches, scripts, and detection content.
- Strong knowledge of OT environments, including SCADA, ICS, industrial network security, asset visibility, threat detection, and Nozomi Networks solutions.
Nice to have
- Experience with Active Directory, Cisco IOS, Microsoft Server, CrowdStrike, Splunk ES, SNORT, Yara, IronPort, Firepower, Palo Alto Cortex XSIAM, Microsoft Sentinel, IBM QRadar, or ManageEngine Log360.
- Security certifications such as CompTIA Security+, Network+, CCNA, CEH, CISSP, Microsoft, AWS, CrowdStrike, or Palo Alto certifications.
Culture & Benefits
- Full-time role with a work model prioritizing in-person collaboration while offering flexibility for wellbeing and individual work styles.
- Global and local collaboration across technology teams, clients, vendors, and technical staff.
- Learning-focused culture with an emphasis on diversity, inclusion, ethics, and corporate citizenship.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →