Назад
Company hidden
7 дней назад

Security Operations Analyst (SIEM Operations and Threat Detection)

Формат работы
remote (только Spain)
Тип работы
fulltime
Грейд
senior
Английский
c1
Страна
Spain
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Operations Analyst (SIEM Operations and Threat Detection) (SIEM/Cybersecurity): Enhancing security monitoring and threat detection capabilities across SIEM, EDR, cloud, and other cybersecurity platforms with an accent on detection content management, data-source onboarding, and quality assurance. Focus on tuning detections, reducing false positives, analyzing security threats, and improving operational metrics and service performance.

Location: Remote position based in València, Spain; participation in a mandatory rotating 24/7 on-call schedule is required.

Company

International consulting group specializing in innovation and business transformation through technology, with more than 7,200 consultants across 21 countries.

What you will do

  • Develop, implement, validate, tune, and maintain security monitoring, analytics, and detection capabilities across SIEM, EDR, cloud, and other cybersecurity platforms.
  • Operate and continuously improve security monitoring and threat detection services.
  • Onboard, integrate, test, and validate security data sources, telemetry feeds, and monitoring capabilities.
  • Manage detection use-case lifecycles, security content reviews, testing, tuning, and quality assurance.
  • Collaborate with threat intelligence, incident response, and cybersecurity operations teams to translate requirements into effective detections.
  • Prepare cybersecurity metrics, dashboards, KPIs, technical reports, procedures, and operational documentation.

Requirements

  • More than 5 years of relevant information technology experience, including alert triage and security incident support.
  • Proven experience administering a SIEM platform, preferably Splunk or Microsoft Sentinel.
  • Experience with SOC tools and autonomous technical analysis of security threats, including collaboration with incident response teams.
  • Deep knowledge of Microsoft Security tools, Azure, AWS, GCP, SIEM platforms, EDR solutions, email security, network monitoring, and incident response.
  • Knowledge of Linux, macOS, and Windows, plus experience with security operations documentation and reporting.
  • C1 English proficiency and mandatory participation in a rotating on-call schedule, approximately one full week every few months.

Nice to have

  • Experience designing and implementing SIEM architectures and log-ingestion pipelines across cloud and on-premises environments.
  • Experience monitoring AWS IaaS, SaaS, and PaaS environments.
  • Knowledge of Ruby, Bash, PowerShell, Python, or another general-purpose or shell scripting language.
  • MCSE, CCNA, Microsoft Azure, GCIH, CEH, GCFA, GIAC, or similar certification.

Culture & Benefits

  • Long-term freelance, full-time contract.
  • Remote work from València, Spain.
  • Training and career development opportunities.
  • Work with a multicultural team on international projects.
  • Customer-facing work requiring communication, cooperation, creativity, and conflict-management skills.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →