7 дней назад
Security Operations Analyst (SIEM Operations and Threat Detection)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Operations Analyst (SIEM Operations and Threat Detection) (SIEM/Cybersecurity): Enhancing security monitoring and threat detection capabilities across SIEM, EDR, cloud, and other cybersecurity platforms with an accent on detection use case lifecycle management, security content quality assurance, and data-source integration. Focus on tuning detections, reducing false positives, analyzing threats, and building operational metrics and reports within a 24/7 on-call environment.
Location: Remote position associated with Warsaw, Poland
Company
is an international consulting group specializing in innovation and business transformation through technology, with expertise in cybersecurity, cloud, data, and application services.
What you will do
- Develop, validate, tune, and maintain security monitoring, analytics, and detection capabilities across SIEM, EDR, cloud, and other cybersecurity platforms.
- Operate and continuously improve security monitoring and threat detection services.
- Onboard, integrate, test, and validate security data sources, telemetry feeds, and monitoring capabilities.
- Manage security content and detection use cases, including rule reviews, testing, tuning, and quality assurance.
- Collaborate with threat intelligence, incident response, and cybersecurity operations teams to translate requirements into effective detections.
- Prepare operational metrics, dashboards, KPIs, technical reports, procedures, and recommendations.
Requirements
- At least 5 years of relevant IT experience, including alert triage and security incident support.
- Experience administering a SIEM platform, preferably Splunk or Microsoft Sentinel, with knowledge of QRadar, ArcSight, and ELK Stack.
- Experience with SOC tools, EDR solutions, threat analysis, incident response, email security, and network monitoring.
- Deep knowledge of Microsoft Security tools and cloud technologies including Azure, AWS, and GCP.
- Knowledge of Linux, macOS, and Windows, plus strong documentation, reporting, communication, and customer-facing skills.
- C1 English proficiency and mandatory participation in a rotating 24/7 on-call system; the approximate rotation is one full week every several months.
Nice to have
- Experience designing and implementing SIEM architectures and data-ingestion pipelines across cloud and on-premises environments.
- Experience monitoring AWS IaaS, SaaS, and PaaS environments.
- Knowledge of Ruby, Bash, PowerShell, Python, or another general-purpose or shell scripting language.
- Certifications such as MCSE, CCNA, Microsoft Azure SC-200, GCIH, CEH, GCFA, or GIAC certifications.
Culture & Benefits
- Remote position with a freelance, full-time contract.
- Training and career development opportunities.
- Work with a multicultural team on international projects.
- Exposure to large-scale cybersecurity environments and diverse customer landscapes.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
7 дней назад
Security Analyst / SOC (Cybersecurity)
7 дней назад
Threat Analyst 2 (Cybersecurity)
10 дней назад
Security Operations Lead (Cybersecurity)
3 350 - 4 800€
8 дней назад
Security Operations Center Engineer (Splunk)
7 дней назад
Global Cybersecurity Operations Analyst
8 дней назад
Associate SOC Analyst (Cybersecurity)
85 000 - 90 000$