Security Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: United States; hybrid work based on the EVOCS floor. Client work is performed from client-provided virtual desktops, covering the Americas business day with rotating weekend shifts. Phoenix provides continuity coverage during declared events.
Salary: $50–$65 per hour, with overtime at time and a half beyond 40 hours per week and a shift differential for evening and weekend rotation.
Company
is an IT consulting firm delivering technology solutions, cybersecurity services, and practical expertise to business clients.
What you will do
- Monitor and triage alerts across endpoint, identity, network, cloud, email, and web application telemetry.
- Validate activity, classify severity, document rationale, and close false positives with recorded explanations.
- Enrich escalations with asset criticality, ownership, identity behavior, exposure context, blast radius, severity, and recommended actions.
- Execute approved containment actions such as host isolation, session revocation, message purges, and block-list changes.
- Maintain cases in client ITSM platforms, page on-call teams, and complete written shift handovers.
- Improve detections through false-positive feedback, threat hunts, and tabletop exercises.
Requirements
- 2–4 years of experience in a SOC, MSSP, incident response team, or equivalent monitoring role.
- Hands-on triage across at least three areas: endpoint, identity, network, cloud, or email.
- Working knowledge of SIEM platforms and the ability to write and refine queries.
- Practical understanding of attack progression, including credential compromise, lateral movement, privilege escalation, persistence, and exfiltration.
- Familiarity with MITRE ATT&CK and clear written English for client-facing escalations.
- Willingness to work rotating shifts across the Americas business day, including weekend rotation, in a hybrid floor-based setup.
Nice to have
- Scripting or query experience with Python, PowerShell, KQL, or SPL.
- Exposure to SOAR playbook maintenance.
- Cloud or security certifications such as SC-200, Security+, CySA+, GCIA, GCIH, or a vendor SIEM credential.
- Experience with operational technology, ICS protocols, IEC 62443, or NIST SP 800-82.
- Experience working to contracted service levels.
Culture & Benefits
- 24x7 security operations delivered across three regions.
- Paid hourly employment with overtime at time and a half after 40 hours per week.
- Shift differential for evening and weekend rotations.
- Client-focused culture emphasizing quality, consistency, integrity, and data-driven decision-making.
- Personal phones and removable media are not permitted at consoles.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →