7 дней назад
Security Operations Analyst (SIEM Operations and Threat Detection)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Operations Analyst (SIEM Operations and Threat Detection) (SIEM/Cybersecurity): Enhancing security monitoring and threat detection capabilities across SIEM, EDR, cloud, and cybersecurity platforms with an accent on detection content management, data-source onboarding, and quality assurance. Focus on tuning detections, reducing false positives, analyzing security threats, and improving operational reporting and service effectiveness.
Location: Remote position associated with Prague, Czech Republic
Company
is an international consulting group specializing in technology-driven innovation, business transformation, cloud, data, and cybersecurity services.
What you will do
- Develop, implement, validate, tune, and maintain security monitoring and detection capabilities across SIEM, EDR, cloud, and other cybersecurity platforms.
- Operate and continuously improve security monitoring and threat detection services.
- Onboard, integrate, test, and validate security data sources, telemetry feeds, and monitoring capabilities.
- Manage security content and detection use-case lifecycles, including rule reviews, testing, tuning, and quality assurance.
- Collaborate with threat intelligence, incident response, and cybersecurity operations teams to translate requirements into effective detections.
- Prepare operational metrics, dashboards, KPIs, technical reports, procedures, and recommendations for stakeholders.
Requirements
- At least 5 years of relevant information technology experience, including alert triage and security incident support.
- Proven experience administering a SIEM platform, preferably Splunk or Microsoft Sentinel, plus experience with SIEM, EDR, and SOC tools.
- Deep knowledge of Microsoft security tools, cloud technologies including Azure, AWS, and GCP, and SIEM platforms such as Splunk, QRadar, ArcSight, Microsoft Sentinel, or ELK Stack.
- Experience with at least one EDR solution, email security, network monitoring, incident response, and Linux, macOS, and Windows environments.
- C1 English proficiency required.
- Mandatory participation in a rotating 24/7 on-call schedule, with approximately one seven-day standby week every few months.
Nice to have
- Experience designing and implementing SIEM architectures and data-ingestion pipelines across cloud and on-premises environments.
- AWS monitoring experience across IaaS, SaaS, and PaaS environments.
- Experience with Ruby, Bash, PowerShell, Python, or another general-purpose or shell scripting language.
- Relevant certifications such as MCSE, CCNA, Microsoft Azure SC-200, GCIH, CEH, GCFA, or GIAC certifications.
Culture & Benefits
- Long-term freelance, full-time contract.
- Remote work associated with Prague.
- Training and career development opportunities.
- Work with a multicultural team on international projects.
- Customer-facing work requiring communication, documentation, cooperation, and innovative problem-solving.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
7 дней назад
Security Analyst / SOC (Cybersecurity)
7 дней назад
Global Cybersecurity Operations Analyst
7 дней назад
Threat Analyst 2 (Cybersecurity)
10 дней назад
Security Operations Lead (Cybersecurity)
3 350 - 4 800€
8 дней назад
Security Operations Center Engineer (Splunk)
7 дней назад