Security Operations Analyst

United ITs
Málaga, Spain
1 day ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
5 years minimum
Working hours
Regular working hours
Languages
English

Tech stack

Amazon Web Services Microsoft Azure Bash Shell Software as a Service Cloud Computing Cyber Security Databases Linux Web Servers Infrastructure as a Service (IaaS) Python (Programming Language) Microsoft Security Essentials
+15 more
Network Intrusion Detection Systems Network Monitoring Platform as a Service (PAAS) Windows PowerShell ArcSight SIEM Tool Ruby Shell Script Security Information and Event Management TCP/IP Transmission Control Protocol (TCP) EndPointSecurity Google Cloud QRadar Information Technology Splunk

Job description

Full Time Valencia, Spain or Remote (CET, LATAM, or IST time zones)Location: Valencia, Spain or remote (EMEA, LATAM, or IST)Teleworking option: YesRequired Technical Skills SCOPE OF WORK:Monitor, triage, and investigate alerts across Microsoft security tools, AWS, SIEM platforms, and EDR solutionsAnalyze network and host-based logs (firewalls, NIDS/HIDS, syslog, etc.) to determine appropriate remediation and escalationIdentify root causes, direct remediation and recovery actions, and support incident response effortsFollow structured analytical processes and collaborate with other analysts and teams to ensure effective threat managementPrepare and present security reports, summaries, and findings to clientsContribute to the improvement of CSOC processes and procedures, including quality control procedures, documentation and knowledge base updatesGather the necessary information from the client to identify opportunities for whitelist tuning and optimization to reduce false positives and enhance detection qualityReviewing feedback and implementing corrective actions to maintain service excellenceProvide other ad hoc support as requiredThe resource MUST have the following skills and experience:A minimum of five (5) years of relevant experience in information technology field, including triage of alerts and supporting security incidentsProven experience with the usual toolbox available in a SOC (e.G., SIEMs, EDRs), able to autonomously perform technical analysis of security threats and collaborate with Incident Response teamTrouble ticket generation and processing experienceExpert knowledge of Windows, Linux, Database, Application, Web server, etc. log analysisKnowledge of Transmission Control Protocol / Internet Protocol (TCP/IP) protocolsDeep knowledge of Microsoft Security Tools (e.G. M365, Cloud App Security, Azure, Defender for Endpoints, Azure Security, Azure Sentinel and XDR)Deep knowledge of Cloud technologies (e.G. Azure, AWS and GCP)Deep knowledge of SIEM tools like Splunk, QRadar, ArcSight, MS Sentinel, ELK StackKnowledge of at least one EDR solution (MS Defender for Endpoint, CrowdStrike)Knowledge of email security, network monitoring, and incident responseKnowledge of Linux/Mac/WindowsExpert knowledge of English, both written and spoken, is requiredThe resource SHOULD have the following skills and experience:Experience on an Incident Response team performing Tier I/II initial incident triage.Proven knowledge of monitoring AWS environment (Iaas, Saas, Paas)Knowledge of at least one general-purpose or shell scripting language (e.G. Ruby, Bash, PowerShell, Python, etc.)Excellent communication skillsCustomer-facing experience and oral communication skillsAbility to write documentation & reportsCreativity/ ability to find innovative solutionsWillingness to learn on the jobConflict management & cooperationDesirable certifications:Technical certifications: MCSE, CCNA, Microsoft Azure (e.G., SC-200), GCIH, CEH, GCFA or any GIAC/similar certificationRelevant industry certifications#J-*****-Ljbffr

Requirements

enhance detection qualityReviewing feedback and implementing corrective actions to maintain service excellenceProvide other ad hoc support as requiredThe resource MUST have the following skills and experience:A minimum of five (5) years of relevant experience in information technology field, including triage of alerts and supporting security incidentsProven experience with the usual toolbox available in a SOC (e.G., SIEMs, EDRs), able to autonomously perform technical analysis of security threats and collaborate with Incident Response teamTrouble ticket generation and processing experienceExpert knowledge of Windows, Linux, Database, Application, Web server, etc. log analysisKnowledge of Transmission Control Protocol / Internet Protocol (TCP/IP) protocolsDeep knowledge of Microsoft Security Tools (e.G. M365, Cloud App Security, Azure, Defender for Endpoints, Azure Security, Azure Sentinel and XDR)Deep knowledge of Cloud technologies (e.G. Azure, AWS and GCP)Deep knowledge of SIEM tools like Splunk, QRadar, ArcSight, MS Sentinel, ELK StackKnowledge of at least one EDR solution (MS Defender for Endpoint, CrowdStrike)Knowledge of email security, network monitoring, and incident responseKnowledge of Linux/Mac/WindowsExpert knowledge of English, both written and spoken, is requiredThe resource SHOULD have the following skills and experience:Experience on an Incident Response team performing Tier I/II initial incident triage.Proven knowledge of monitoring AWS environment (Iaas, Saas, Paas)Knowledge of at least one general-purpose or shell scripting language (e.G. Ruby, Bash, PowerShell, Python, etc.)Excellent communication skillsCustomer-facing experience and oral communication skillsAbility to write documentation & reportsCreativity/ ability to find innovative solutionsWillingness to learn on the jobConflict management & cooperationDesirable certifications:Technical certifications: MCSE, CCNA, Microsoft Azure (e.G., SC-200), GCIH, CEH, GCFA or any GIAC/similar certificationRelevant industry certifications#J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Loading talks and stories from around this role…