7 дней назад
Security Operations Analyst (SIEM Operations and Threat Detection)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Operations Analyst (SIEM Operations and Threat Detection) (SIEM/Cybersecurity): Enhancing security monitoring and threat detection capabilities across SIEM, EDR, cloud, and other cybersecurity platforms with an accent on detection content management, data-source onboarding, and quality assurance. Focus on tuning detections, reducing false positives, analyzing security threats, and improving operational metrics and service performance.
Location: Remote position based in València, Spain; participation in a mandatory rotating 24/7 on-call schedule is required.
Company
International consulting group specializing in innovation and business transformation through technology, with more than 7,200 consultants across 21 countries.
What you will do
- Develop, implement, validate, tune, and maintain security monitoring, analytics, and detection capabilities across SIEM, EDR, cloud, and other cybersecurity platforms.
- Operate and continuously improve security monitoring and threat detection services.
- Onboard, integrate, test, and validate security data sources, telemetry feeds, and monitoring capabilities.
- Manage detection use-case lifecycles, security content reviews, testing, tuning, and quality assurance.
- Collaborate with threat intelligence, incident response, and cybersecurity operations teams to translate requirements into effective detections.
- Prepare cybersecurity metrics, dashboards, KPIs, technical reports, procedures, and operational documentation.
Requirements
- More than 5 years of relevant information technology experience, including alert triage and security incident support.
- Proven experience administering a SIEM platform, preferably Splunk or Microsoft Sentinel.
- Experience with SOC tools and autonomous technical analysis of security threats, including collaboration with incident response teams.
- Deep knowledge of Microsoft Security tools, Azure, AWS, GCP, SIEM platforms, EDR solutions, email security, network monitoring, and incident response.
- Knowledge of Linux, macOS, and Windows, plus experience with security operations documentation and reporting.
- C1 English proficiency and mandatory participation in a rotating on-call schedule, approximately one full week every few months.
Nice to have
- Experience designing and implementing SIEM architectures and log-ingestion pipelines across cloud and on-premises environments.
- Experience monitoring AWS IaaS, SaaS, and PaaS environments.
- Knowledge of Ruby, Bash, PowerShell, Python, or another general-purpose or shell scripting language.
- MCSE, CCNA, Microsoft Azure, GCIH, CEH, GCFA, GIAC, or similar certification.
Culture & Benefits
- Long-term freelance, full-time contract.
- Remote work from València, Spain.
- Training and career development opportunities.
- Work with a multicultural team on international projects.
- Customer-facing work requiring communication, cooperation, creativity, and conflict-management skills.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
7 дней назад
Security Analyst / SOC (Cybersecurity)
8 дней назад
Security Operations Center Engineer (Splunk)
7 дней назад
Threat Analyst 2 (Cybersecurity)
7 дней назад
Senior Specialist, Incident Response (Cybersecurity)
7 дней назад
Global Cybersecurity Operations Analyst
10 дней назад
Security Engineer - Incident Response (Cybersecurity)
70 000 - 107 800€