← All jobs

Security Operations Analyst

About the role

• Monitor and triage real-time alerts across EDR, firewall, IPS, WAF, and SIEM platforms
• Prioritize alert severity and distinguish true positives under time pressure
• Maintain continuous 24x7 threat monitoring through rotating shifts, including nights, weekends, and holidays
• Conduct deep incident investigations by correlating EDR, network, and cloud telemetry
• Determine incident root cause, scope, and indicators of compromise
• Provide incident analysis, containment recommendations, and remediation guidance to client teams
• Refine SIEM correlation rules and detection logic to eliminate false positives and close coverage gaps
• Document investigation findings and incident timelines in case management systems
• Update SOC playbooks and standard operating runbooks
• Partner with GRC engineers and vCISOs to align threat detection with client compliance obligations
• Execute investigation handoffs across shift rotations
• Guide junior analysts on investigative techniques
• Partner directly with client stakeholders to maintain strong detection coverage

• 3+ years of hands-on experience monitoring, triaging, and investigating security alerts within a high-velocity SOC setting
• Skilled at correlating data across EDR, firewall, IPS, WAF, and SIEM tools
• Ability to own complex investigations end to end and make sound escalation decisions with minimal oversight
• Ability to document findings and explain complex technical incidents in plain language to client stakeholders
• Willingness and ability to work a 24x7 rotating shift schedule, including nights, weekends, and holidays
• Recognized security credential such as CompTIA Security+, CySA+, GCIH, or equivalent credentials
• Practical experience with EDR tools such as CrowdStrike, SentinelOne, and Defender
• Practical experience with SIEM solutions such as Splunk, Microsoft Sentinel, Sumo Logic, and Wazuh
• Experience configuring, maintaining, and tuning security platforms beyond day-to-day alert triage
• Proficiency writing Python or PowerShell scripts and developing SOAR playbooks
• Prior experience in managed security service provider environments supporting multiple client organizations concurrently
• Familiarity with SOC 2, ISO 27001, and HIPAA requirements as they align with threat detection and incident response
• Excellent written and verbal English communication skills
• Reliable, high-speed internet connection and a professional home office environment supporting confidential conversations and uninterrupted shift coverage
• Willingness to travel locally for occasional onsite meetings, team gatherings, or business activities
• Participation in live video interviews with camera on and identity verification during recruitment and onboarding
• Successful identity verification and background screening, where permitted by law

• Clear career path with mentorship and training opportunities
• Reimbursement for successful completion of approved training and certification courses relevant to the current role
• Competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities
• Significant room for career advancement
• Remote-first flexibility to work from anywhere while collaborating with a global team, within the assigned shift