SOC Analyst

Auxis

Bogotá

Presencial

COP 40.000.000 - 70.000.000

Jornada completa

Hace 8 días
Generador de candidaturas

Destaca para este puesto: genera un currículum y una carta de presentación adaptados en cuestión de un minuto.

Supera los filtros ATS

Descripción de la vacante

Grant Thornton's Cyber Fusion Centre (CFC) is seeking a technically strong SOC Analyst to join a follow-the-sun security operations team in Bogotá. You will handle continuous monitoring, alert triage, incident investigation, threat analysis, and remediation coordination using CrowdStrike Falcon Next-Gen SIEM and related tools.

The role covers the full security operations lifecycle, including investigation, documentation, escalation, and improvement of detection and response capabilities, in a

Formación

  • 2+ years of experience in security operations, SOC monitoring, SIEM operations, EDR, MDR, incident response or related cybersecurity role.
  • Hands-on experience with CrowdStrike Falcon Next-Gen SIEM/EDR.
  • Experience with ServiceNow or similar ITSM/security case management platform.
  • Bachelor's degree in CS/InfoSec or related discipline preferred.

Responsabilidades

  • Monitor real-time security with CrowdStrike Falcon Next-Gen SIEM; perform alert triage and incident investigations.
  • Coordinate containment, eradication, and recovery activities per SOC playbooks.
  • Produce investigation reports and maintain evidence notes in the case management system.
  • Support threat analysis, detection validation, and continuous improvement initiatives.

Conocimientos

SOC operations
SIEM operations
EDR
Incident response
Information security
Clear communication

Educación

Bachelor's degree in Computer Science / Information Security
Equivalent practical cybersecurity experience

Herramientas

CrowdStrike Falcon
ServiceNow
ITSM security

Descripción del empleo

Job Summary

Grant Thornton's Cyber Fusion Centre (CFC) is looking for a technically strong, motivated

Job Summary

Grant Thornton's Cyber Fusion Centre (CFC) is looking for a technically strong, motivated SOC Analyst to join a follow-the-sun security operations team. This is a hands-on role covering continuous monitoring, alert triage, incident investigation, threat analysis, incident response support, remediation coordination, documentation, and ongoing improvement of detection and response capability.

The CFC operates a tierless SOC model — analysts own the full security operations lifecycle, from initial alert review and triage through investigation, containment support, escalation, documentation, closure, and improvement recommendations.

The primary platform is CrowdStrike Falcon Next-Gen SIEM. Analysts should be comfortable querying and analyzing security data, interpreting detections, correlating events across data sources, assessing suspicious or malicious activity, contributing to investigations, using dashboards and case management tools, and producing clear reporting.

Responsibilities
Security Monitoring & Alert Triage
  • Use CrowdStrike Falcon Next-Gen SIEM as the primary platform for real-time monitoring, query-based analysis, detection review, event correlation, case management, and reporting.
  • Review, prioritize, and classify alerts using the established severity matrix and SOC operating procedures.
  • Determine whether alerts represent false positives, benign activity, suspicious activity, policy violations, or potential security incidents.
  • Conduct triage, detailed investigation, evidence review, response coordination, and closure documentation for assigned alerts and incidents.
  • Analyze and interpret first-party detections, third-party detections, and correlation rule outputs.
  • Maintain accurate triage decisions, evidence notes, and investigation updates in the incident management platform.
Incident Response & Remediation
  • Ensure incidents are handled promptly in line with SOC runbooks, escalation workflows, and operational expectations.
  • Execute approved Cybersecurity Incident Response Plan activities and associated SOC playbooks.
  • Support containment, eradication, and recovery activities in coordination with IT resolver teams, platform engineering, IAM, network security, email security, and infrastructure teams.
  • Escalate confirmed major incidents to CSIRT or management stakeholders when escalation criteria are met.
  • Assist with root cause analysis documentation for major incidents, repeat incidents, or incidents requiring formal review.
Threat Analysis & Continuous Improvement
  • Support threat hunting, detection validation, and investigation workflows using Falcon Next-Gen SIEM.
  • Identify vulnerabilities, suspicious activity, threats, exploits, and weaknesses in security controls.
  • Create visualizations, summaries, and investigation reports to communicate event details to SOC leadership and operational stakeholders.
  • Recommend improvements to detection logic, correlation rules, dashboards, alert handling procedures, and SOC runbooks.
  • Review internal and external threat intelligence advisories, indicators of compromise, and relevant adversary activity.
  • Support SOC metrics, quality checks, reporting, and continuous improvement initiatives.
  • Support audit, compliance, and evidence requests as required.
Shift & Operational Requirements
  • Operate within 24x7 security operations and incident response environment.
  • Work within a tierless SOC where each analyst may handle triage, investigation, response coordination, documentation, escalation, and closure activities.
  • Communicate clearly with technical teams, business stakeholders, management, and, where relevant, legal/privacy and communications teams.
  • Follow structured incident response, evidence handling, reporting, and documentation practices.
Required Qualifications
Skills and Experience
  • English Level B2+
Experience
  • 2+ years of experience in security operations, SOC monitoring, SIEM operations, EDR, MDR, incident response, information security, or a related cybersecurity role.
  • Experience working in a SOC, MDR, MSSP, enterprise security operations, or similar operational environment.
  • Hands-on experience with CrowdStrike Falcon Next-Gen SIEM / EDR strongly preferred.
  • Experience with ServiceNow or a similar ITSM/security case management platform.
Education
  • Bachelor's degree in computer science, Information Security, Cybersecurity, or a related discipline preferred.
  • Equivalent practical experience in cybersecurity operations, incident response, threat hunting, or digital forensics will also be considered.
Certifications (Preferred)
  • CrowdStrike Certified SIEM Analyst (CCSA)
  • CompTIA CySA+
  • Other SOC, SIEM, incident response, network security, or digital forensics certifications
Core Competencies
  • Strong hands-on information security skills
  • Strong incident investigation and analytical reasoning skills
  • Ownership mindset with strong attention to detail
  • Solid understanding of MITRE ATT&CK and the incident response lifecycle
  • Excellent written and verbal communication skills
  • Ability to brief both technical and non-technical stakeholders
  • Strong organization, time management, and attention to detail
  • Calm, structured decision-making under high-pressure incidents
  • Ability to work independently and as part of a team
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

CSIRT Incident Responder / Threat Hunter
CSIRT Incident Responder / Threat Hunter

Auxis LLC • Bogotá

Presencial
COP 90.000.000 - 120.000.000
CSIRT Incident Responder / Threat Hunter
CSIRT Incident Responder / Threat Hunter

Auxis • Bogotá

Presencial
COP 90.000.000 - 180.000.000
SOC Analyst - 24/7 Tierless Ops with Falcon SIEM
SOC Analyst - 24/7 Tierless Ops with Falcon SIEM

Auxis • Bogotá

Presencial
COP 40.000.000 - 70.000.000
CrowdStrike Falcon EDR Security Engineer
CrowdStrike Falcon EDR Security Engineer

Auxis LLC • Bogotá

Presencial
COP 60.000.000 - 90.000.000
CrowdStrike Falcon EDR Security Engineer
CrowdStrike Falcon EDR Security Engineer

Auxis • Bogotá

Presencial
COP 60.000.000 - 120.000.000
Senior CSIRT Incident Responder & Threat Hunter
Senior CSIRT Incident Responder & Threat Hunter

Auxis LLC • Bogotá

Presencial
COP 90.000.000 - 120.000.000
SOC Coordinator
SOC Coordinator

S2GRUPO • Bogotá

Presencial
COP 112.750.000 - 187.917.000
S2 Grupo
SOC Coordinator
SOC Coordinator

S2 Grupo • Bogotá

Presencial
COP 90.000.000 - 130.000.000
Senior CSIRT Incident Responder & Threat Hunter
Senior CSIRT Incident Responder & Threat Hunter

Auxis • Bogotá

Presencial
COP 90.000.000 - 180.000.000
Regional Sales Manager (Remote, Medellin)
Regional Sales Manager (Remote, Medellin)

CrowdStrike Holdings, Inc. • Medellín

Híbrido
COP 373.750.000 - 560.625.000
Market-leading compensation
Wellness programs
Generous vacation
+2