SOC Analyst
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
SOC Analyst: Monitoring and triaging security alerts across SIEM, EDR, cloud, email, and identity platforms with an accent on incident investigation, true/false positive differentiation, and structured escalation. Focus on collecting and preserving investigation artifacts, maintaining accurate case notes, and supporting detection tuning while working shifts aligned with U.S. business hours.
Location: Remote: Brazil, Ecuador, Colombia, Mexico (LATAM)
Company
provides an automated endpoint management platform for visibility, security, and control across endpoints.
What you will do
- Monitor security alerts and events across SIEM, EDR, cloud, email, and identity platforms
- Perform initial triage to assess severity, scope, and potential impact
- Use playbooks and investigative techniques to distinguish true positives from false positives
- Escalate confirmed or high-risk incidents to Tier 2/DFIR teams with clear, structured documentation
- Collect and preserve artifacts (logs, indicators, timelines) and maintain accurate case notes and ticket updates
- Support shift handoffs and contribute to detection tuning and process improvements
Requirements
- English resumes required and strong written English skills for documentation and escalation
- 1–3 years of experience in a SOC, NOC, IT security, or related technical role
- Basic understanding of security monitoring and alert triage
- Foundational networking knowledge (TCP/IP, DNS, HTTP/S) and familiarity with Windows and/or macOS
- Understanding of common attack techniques (phishing, brute force, malware) and cloud misconfigurations
- Ability to work scheduled shifts aligned with U.S. business hours (including occasional weekends or on-call)
Culture & Benefits
- Flexible working hours with home office options
- Training and skill development through a dedicated training platform
- Competitive compensation
- Collaboration with an international workforce
Hiring process
- Review of English resume and application details
- Interviews focused on SOC operations, alert triage, and incident escalation approach
- Final evaluation of shift availability aligned with U.S. business hours
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →