← Zurück zur Liste

Stelle
Security Operations Analyst (SIEM Operations and Threat Detection)
Security Engineer
• Hybrid
• Vollzeit
•
Vigo, Spanien
Senior consultant role in a globally distributed Cyber Security Operations Center (CSOC), focused on improving threat detection and security operations. Remote, freelance full-time contract.
Responsibilities
- ▹Contribute to the development, implementation, validation, tuning and maintenance of security monitoring, analytics and detection capabilities across SIEM, EDR, cloud and other cybersecurity platforms
- ▹Support the operation, maintenance, optimization and continuous improvement of security monitoring and threat detection services
- ▹Participate in the onboarding, integration, testing and validation of security data sources, telemetry feeds and monitoring capabilities
- ▹Contribute to security content management, including use case lifecycle management, rule reviews, testing, tuning and content quality assurance
- ▹Collaborate with cyber threat intelligence, incident response and cybersecurity operations teams to translate operational and threat intelligence requirements into effective detection and monitoring capabilities
- ▹Under guidance, participate in cybersecurity architecture reviews of new or existing solutions and recommend improvements to monitoring and detection effectiveness
- ▹Contribute to the preparation and maintenance of cybersecurity operations metrics, dashboards, KPIs and service performance reports
- ▹Review, validate and assess the effectiveness of detections, monitoring configurations, operational processes and service deliverables
- ▹Gather and analyze operational feedback to identify opportunities for tuning, optimization, reducing false positives and improving detection quality
- ▹Contribute to quality assurance activities, including process reviews, control validation, service quality assessments and corrective actions
- ▹Support the development, review and maintenance of CSOC procedures, standards, documentation, knowledge base articles and operational guidance
- ▹Prepare and present technical reports, summaries, findings and recommendations to internal and external stakeholders
- ▹Take part in a rotating on-call shift schedule from Monday to Sunday: you are on standby outside standard working hours and only log in to resolve critical incidents if they arise
Requirements
- ▹5+ years of relevant experience in information technology, including triage of alerts and supporting security incidents
- ▹Proven experience administering a SIEM platform, preferably Splunk or Microsoft Sentinel
- ▹Experience with the usual SOC toolbox (e.g. SIEMs, EDRs) and the ability to autonomously perform technical analysis of security threats and collaborate with the Incident Response team
- ▹Deep knowledge of Microsoft Security tools (e.g. M365, Cloud App Security, Azure, Defender for Endpoint, Azure Security, Azure Sentinel and XDR)
- ▹Deep knowledge of cloud technologies (e.g. Azure, AWS and GCP)
- ▹Deep knowledge of SIEM tools such as Splunk, QRadar, ArcSight, MS Sentinel, ELK Stack
- ▹Knowledge of at least one EDR solution (MS Defender for Endpoint, CrowdStrike)
- ▹Knowledge of email security, network monitoring and incident response
- ▹Knowledge of Linux, Mac and Windows
Nice to have
- ▹Experience building SIEM architectures from initial design to implementation, including designing data ingestion pipelines for diverse log sources across cloud and on-prem environments
- ▹Proven knowledge of monitoring AWS environments (IaaS, SaaS, PaaS)
- ▹Knowledge of at least one general-purpose or shell scripting language (e.g. Ruby, Bash, PowerShell, Python)
- ▹Desirable certifications: MCSE, CCNA, Microsoft Azure (e.g. SC-200), GCIH, CEH, GCFA or any GIAC or similar certification
Soft skills
Excellent communication skillsCustomer-facing experience and oral communication skillsAbility to write documentation and reportsCreativity and ability to find innovative solutionsWillingness to learn on the jobConflict management and cooperation
What we offer
- ▹Remote position
- ▹Freelance, full-time contract
- ▹Training and career development
- ▹Multicultural team and international projects
About the company
Talan is an international consulting group that supports innovation and business transformation through technology. It has over 7,200 consultants in 21 countries and is headquartered in Paris.
Languages: Angol: C1
Ähnliche Stellen

Stelle
Security Operations Analyst (SIEM Operations and Threat Detection)
Talan
Data Science
+8
💰 Gehalt: keine Angabe
🏢 Vor Ort
València
🗣️ EN

Stelle
Security Operations Analyst (SIEM & Threat Detection)
Pragmatike
+4
💰 Gehalt: keine Angabe
🌍 Remote
🗣️ EN

Stelle
Security Operations Analyst (Cyber Defense Operations)
Pragmatike
+4
💰 Gehalt: keine Angabe
🌍 Remote
🗣️ EN

Stelle
Cybersecurity Consultant (German & English Speaking) - EY GDS Spain - Hybrid
EY
Powershell
+3
💰 Gehalt: keine Angabe
🏢 Vor Ort
Malaga
🗣️ EN

Stelle
Cybersecurity Analyst - RDT Security Platforms
Roche
+7
💰 Gehalt: keine Angabe
🏢 Vor Ort
Madrid
🗣️ EN

Stelle
Infrastructure Security Engineer – London
SpaceXAI
AI/MLCloudformation
+8
💰 Gehalt: keine Angabe
🏢 Vor Ort
Dublin
🗣️ EN