Назад
Company hidden
7 дней назад

Security Operations Analyst (SIEM Operations and Threat Detection)

Формат работы
remote (только Czech_republic)
Тип работы
fulltime
Грейд
senior
Английский
c1
Страна
CR
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Operations Analyst (SIEM Operations and Threat Detection) (SIEM/Cybersecurity): Enhancing security monitoring and threat detection capabilities across SIEM, EDR, cloud, and cybersecurity platforms with an accent on detection content management, data-source onboarding, and quality assurance. Focus on tuning detections, reducing false positives, analyzing security threats, and improving operational reporting and service effectiveness.

Location: Remote position associated with Prague, Czech Republic

Company

hirify.global is an international consulting group specializing in technology-driven innovation, business transformation, cloud, data, and cybersecurity services.

What you will do

  • Develop, implement, validate, tune, and maintain security monitoring and detection capabilities across SIEM, EDR, cloud, and other cybersecurity platforms.
  • Operate and continuously improve security monitoring and threat detection services.
  • Onboard, integrate, test, and validate security data sources, telemetry feeds, and monitoring capabilities.
  • Manage security content and detection use-case lifecycles, including rule reviews, testing, tuning, and quality assurance.
  • Collaborate with threat intelligence, incident response, and cybersecurity operations teams to translate requirements into effective detections.
  • Prepare operational metrics, dashboards, KPIs, technical reports, procedures, and recommendations for stakeholders.

Requirements

  • At least 5 years of relevant information technology experience, including alert triage and security incident support.
  • Proven experience administering a SIEM platform, preferably Splunk or Microsoft Sentinel, plus experience with SIEM, EDR, and SOC tools.
  • Deep knowledge of Microsoft security tools, cloud technologies including Azure, AWS, and GCP, and SIEM platforms such as Splunk, QRadar, ArcSight, Microsoft Sentinel, or ELK Stack.
  • Experience with at least one EDR solution, email security, network monitoring, incident response, and Linux, macOS, and Windows environments.
  • C1 English proficiency required.
  • Mandatory participation in a rotating 24/7 on-call schedule, with approximately one seven-day standby week every few months.

Nice to have

  • Experience designing and implementing SIEM architectures and data-ingestion pipelines across cloud and on-premises environments.
  • AWS monitoring experience across IaaS, SaaS, and PaaS environments.
  • Experience with Ruby, Bash, PowerShell, Python, or another general-purpose or shell scripting language.
  • Relevant certifications such as MCSE, CCNA, Microsoft Azure SC-200, GCIH, CEH, GCFA, or GIAC certifications.

Culture & Benefits

  • Long-term freelance, full-time contract.
  • Remote work associated with Prague.
  • Training and career development opportunities.
  • Work with a multicultural team on international projects.
  • Customer-facing work requiring communication, documentation, cooperation, and innovative problem-solving.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →