Назад
Company hidden
4 дня назад

SOC Analyst (AI)

Формат работы
remote
Тип работы
fulltime
Грейд
junior
Английский
b2
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
SOC Analyst (AI) (Cybersecurity/SIEM/EDR): Monitoring, investigating, and responding to security events across corporate and product environments with an accent on incident response, detection engineering, threat intelligence, and AI-assisted analysis. Focus on collecting forensic evidence, building MITRE ATT&CK-aligned detections, integrating LLM-based workflows, and protecting privileged access infrastructure.

Company

Develops cybersecurity SaaS solutions for privileged access management and identity security, protecting enterprise infrastructure and customer environments from sophisticated threats.

What you will do

  • Monitor and triage security alerts across SIEM, EDR, CSPM, and cloud-native log sources.
  • Investigate and respond to incidents, including evidence collection, forensic analysis, root cause determination, remediation, and stakeholder communication.
  • Design, tune, and validate detection rules, reduce false positives, and map coverage to MITRE ATT&CK.
  • Translate threat intelligence into detection content focused on privileged access tooling and supply chain attack vectors.
  • Use and improve AI-assisted triage, enrichment, investigation, prompt, agent, and LLM-based workflows.
  • Maintain runbooks, handoff documentation, operational metrics, and participate in on-call rotations, tabletop exercises, and purple team activities.

Requirements

  • 2+ years of experience in a SOC, security operations, or incident response role.
  • Understanding of MITRE ATT&CK, network protocols, and endpoint behavior.
  • Experience with at least one SIEM platform and writing search or detection queries.
  • Familiarity with EDR platforms and cloud environments, preferably IaaS.
  • Comfort using AI systems, LLM-based assistants, copilots, or AI-driven analysis tools in security workflows.
  • Strong written communication skills for documenting findings for technical and non-technical audiences.

Nice to have

  • Experience leading complex incident response engagements from triage through remediation.
  • Experience with identity and access management, cloud security posture management, SOAR, or orchestration tools.
  • Scripting and automation skills with Python, PowerShell, or equivalent.
  • Experience with AI agent architectures, LLM-based automation pipelines, prompt engineering, threat intelligence programs, or detection-as-code.
  • Understanding of privileged access management threats and experience adopting emerging technologies in production security environments.

Culture & Benefits

  • Collaborative environment with threat hunters, incident responders, and detection engineers.
  • Culture focused on flexibility, trust, continual learning, diversity, and inclusion.
  • Opportunity to contribute to an AI-augmented security operations model.
  • Participation in a global cybersecurity organization serving enterprise customers.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →