← Todas as vagas

Security Operations Analyst

Sobre a vaga

• Monitor alerts across EDR, firewall, IPS, WAF, and SIEM platforms in real time
• Triage alerts, prioritize severity, and distinguish true positives under time pressure
• Maintain continuous 24x7 threat monitoring through rotating shifts, including nights, weekends, and holidays
• Conduct deep incident investigations across EDR, network, and cloud log sources
• Determine incident root cause, scope, and indicators of compromise
• Provide incident analysis and containment recommendations to client teams that own response execution
• Tune SIEM correlation rules and detection logic to reduce false positives and close security coverage gaps
• Document investigation findings and incident timelines in case management systems
• Update SOC playbooks and standard operating runbooks
• Partner with GRC engineers and vCISOs to align threat detection with client compliance obligations
• Execute investigation handoffs across shift rotations
• Guide junior analysts on investigative techniques
• Partner directly with client stakeholders to maintain detection coverage around the clock

• 3+ years of hands-on experience monitoring, triaging, and investigating security alerts within a high-velocity SOC setting
• Skilled at correlating data across EDR, firewall, IPS, WAF, and SIEM tools to trace root causes under pressure
• Ability to own complex investigations end to end and make sound escalation calls with minimal oversight
• Ability to document findings and explain complex technical incidents in plain language to client stakeholders
• Willingness and ability to work a 24x7 rotating shift schedule, including nights, weekends, and holidays
• Recognized industry security credentials such as CompTIA Security+, CySA+, GCIH, or equivalent credentials
• Practical experience with EDR tools such as CrowdStrike, SentinelOne, and Defender
• Practical experience with SIEM solutions such as Splunk, Microsoft Sentinel, Sumo Logic, and Wazuh
• Experience configuring, maintaining, and tuning security platforms beyond day-to-day alert triage
• Proficiency writing Python or PowerShell scripts and developing SOAR playbooks
• Prior experience in managed security service provider environments supporting multiple client organizations concurrently
• Awareness of SOC 2, ISO 27001, and HIPAA requirements as they align with threat detection and incident response operations
• Excellent written and verbal English communication skills
• Reliable, high-speed internet connection and professional home office environment supporting confidential conversations and uninterrupted shift coverage
• Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities
• Must participate in live video interviews with camera on and verify identity during recruitment and onboarding
• Employment contingent upon successful identity verification and background screening, where permitted by law

• Career development with mentorship and training opportunities
• Reimbursement for approved training and certification courses relevant to the current role
• Competitive base salary with regular performance reviews linked to merit-based appraisals
• Bonus opportunities
• Significant room for career advancement
• Remote-first flexibility to work from anywhere while collaborating with a global team, within the assigned shift