7 дней назад
Security Operations Analyst (SIEM Operations and Threat Detection)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Operations Analyst (SIEM Operations and Threat Detection) (SIEM/Cybersecurity Operations): Enhancing security monitoring and threat detection capabilities across SIEM, EDR, cloud, and other cybersecurity platforms with an accent on detection content management, data-source onboarding, and quality assurance. Focus on tuning detections, reducing false positives, validating monitoring controls, and improving CSOC services across complex customer environments.
Location: Remote position associated with Valletta, Malta; participation in a rotating 24/7 on-call standby schedule is mandatory, with approximately one full week every few months.
Company
International consulting group specializing in innovation, business transformation, technology, cloud, data, and cybersecurity services for global clients.
What you will do
- Develop, implement, validate, tune, and maintain security monitoring, analytics, and detection capabilities across SIEM, EDR, cloud, and other cybersecurity platforms.
- Operate and continuously improve security monitoring and threat detection services.
- Onboard, integrate, test, and validate security data sources, telemetry feeds, and monitoring capabilities.
- Manage detection use-case lifecycles, including rule reviews, testing, tuning, and security content quality assurance.
- Collaborate with threat intelligence, incident response, and cybersecurity operations teams to translate requirements into effective detections.
- Prepare dashboards, KPIs, service reports, technical documentation, findings, and recommendations for stakeholders.
Requirements
- At least 5 years of relevant information technology experience, including alert triage and security incident support.
- Proven experience administering a SIEM platform, preferably Splunk or Microsoft Sentinel, with knowledge of QRadar, ArcSight, and ELK Stack.
- Experience with SOC tools, autonomous technical threat analysis, incident response collaboration, and at least one EDR solution such as Microsoft Defender for Endpoint or CrowdStrike.
- Deep knowledge of Microsoft Security tools, Azure, AWS, GCP, email security, network monitoring, incident response, and Linux, macOS, and Windows.
- C1 English proficiency and mandatory participation in the rotating on-call shift system.
- Strong communication, customer-facing, documentation, reporting, problem-solving, learning, and cooperation skills.
Nice to have
- Experience designing and implementing SIEM architectures and data-ingestion pipelines across cloud and on-premises environments.
- Experience monitoring AWS IaaS, SaaS, and PaaS environments.
- Knowledge of Ruby, Bash, PowerShell, Python, or another general-purpose or shell scripting language.
- Certifications such as MCSE, CCNA, Microsoft Azure SC-200, GCIH, CEH, GCFA, GIAC, or similar.
Culture & Benefits
- Freelance, full-time contract.
- Remote work within an international and multicultural environment.
- Training and career development opportunities.
- Work on international cybersecurity projects for diverse customer environments.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
7 дней назад
Security Analyst / SOC (Cybersecurity)
8 дней назад
Security Operations Center Engineer (Splunk)
10 дней назад
Security Engineer - Incident Response (Cybersecurity)
70 000 - 107 800€
7 дней назад
Threat Analyst 2 (Cybersecurity)
12 дней назад
Threat Hunter (Cybersecurity)
7 дней назад