Security Operations Analyst monitoring security events and responding to incidents. Collaborating with IT and Security teams to implement preventive controls and improve processes.
Responsibilities
Continuous monitoring of security events and alerts using SIEM platforms.
Analysis and correlation of logs to identify suspicious activity or indicators of compromise (IoCs).
Develop security use cases aligned with frameworks such as MITRE ATT&CK and internal policies.
Define correlation rules for threat detection (e.g., anomalous behavior, brute-force attacks, data exfiltration).
Tune thresholds and alert logic to reduce false positives.
Parser development and log normalization.
Create custom parsers to integrate new log sources into the SIEM.
Ensure data normalization (mapping to standard fields such as IP, user, action).
Validate log quality and consistency to prevent correlation failures.
Work with common formats (Syslog, JSON, XML) and protocols (CEF, LEEF).
Operation and automation with SOAR, creating playbooks for fast and efficient response.
Triage and handling of security incidents according to criticality and impact.
Investigations across endpoints, networks and applications to determine root cause.
Escalation and communication with internal teams and vendors when necessary.
Detailed documentation of incidents, actions taken, and mitigation recommendations.
Contribute to continuous improvement of monitoring and response processes.
Participate in incident simulation and tabletop exercises.
Collaborate with IT and Security teams to implement preventive controls.
Requirements
Bachelor's degree in Information Security, Cyber Defense, IT or related fields.
Postgraduate degree in Cyber Security, Forensics, Intelligence or Security Architecture is a plus.
Experience with SIEMs (Splunk, QRadar, SecOps, Elastic, Sentinel).
Experience in security incident response.
Experience with Windows and Linux operating systems.
Knowledge of query languages (SPL, AQL, KQL).
Familiarity with regex for parser creation.
Understanding of log formats and protocols.
Basics of SOAR automation (Python, YAML).
Knowledge of MITRE ATT&CK, IOCs, and TTPs.
Knowledge and hands-on experience with security solutions such as WAF, Firewall, IPS, Anti-Malware, EDR, ATP for detection and containment of security incidents.
Availability for on-call shifts on weekends and holidays.
Security Operations Manager overseeing safety measures for corporate office locations and events at Whatnot. Responsible for developing security frameworks and managing vendor relationships across global operations.
Manager overseeing technical security operations for the Protection Services department. Responsible for managing security systems, staff training, and interdepartmental collaboration.
Principal in Security Monitoring Response at Mastercard managing global crises and resilience operations. Leading incident response efforts and ensuring the safety of people and assets.
SOC Analyst II providing real time security monitoring and threat hunting services for clients in various industries. Assisting in identifying security incidents and managing vulnerabilities.
Security Incident Response Orchestration Lead at Bank of America defining automation for security incident workflows with a focus on Splunk SOAR and Tines. Collaborating with security operations and engineering teams to implement scalable solutions.
SOC Analyst II providing tier II cybersecurity support in a Security Operations Center environment. Conducting vulnerability assessments and analyzing cyber threats while training junior staff members.
Security Operations Analyst responsible for monitoring and responding to cybersecurity threats. Ensuring the confidentiality, integrity, and availability of data per compliance standards.
SOC Analyst responsible for cybersecurity incident management at Algosystems in Greece. Monitoring security threats, conducting investigations, and improving SOC services.
Cyber Operations Lead ensuring coordination of cyber operations between the Security Operations Center and internal business units. Enhancing security through effective incident response and threat management initiatives.