Security Operations Analyst (Cyber Defense Operations)

Pragmatike

Puglia

Ibrido

EUR 70.000 - 110.000

Tempo pieno

2 giorni fa
Candidati tra i primi
Generatore di candidature

Distinguiti per questo ruolo — genera un curriculum personalizzato e una lettera di presentazione in circa un minuto.

Supera i filtri ATS

Descrizione del lavoro

Pragmatike is recruiting for a Security Operations Analyst to join a global SOC team. This hands-on role focuses on alert triage, threat investigation, log analysis, incident response, and security monitoring across enterprise, cloud, and network environments.

You’ll work with cybersecurity specialists distributed across regions in a 24/7 SOC setting, analyzing events from SIEM/EDR tools and Microsoft security tech, with opportunities to optimize detection and response processes.

Competenze

  • 5+ years in IT/cybersecurity with security alert triage and incident support.
  • Hands-on SOC experience in a Security Operations Center.
  • Strong experience with SIEM and EDR platforms.
  • Advanced log analysis across Windows, Linux, databases, apps and infra.
  • Knowledge of Microsoft security tech, including Defender and Sentinel.
  • Cloud security experience with Azure, AWS, and/or GCP.
  • Experience with Splunk/QRadar/ArcSight/ELK and Defender for Endpoint.
  • Fluent English with excellent written and verbal communication.

Mansioni

  • Monitor, triage, and investigate security alerts across SIEM, EDR, and cloud platforms.
  • Analyze host and network logs from Windows, Linux, databases, apps, and servers.
  • Investigate suspicious activity, identify root causes, and determine remediation/escalation.
  • Support incident response, remediation, and recovery activities.
  • Collaborate with Incident Response and security teams to manage threats.
  • Prepare security reports and technical findings for stakeholders.
  • Contribute to SOC procedures, knowledge bases, and quality controls.
  • Review operational feedback and implement corrective actions.

Conoscenze

SOC experience
SIEM platforms
EDR platforms
Cloud security
OS knowledge (Windows/Linux/macOS)
Microsoft Defender
Threat detection
Incident response

Strumenti

Splunk
QRadar
ArcSight
ELK
Microsoft Sentinel
Defender for Endpoint

Descrizione del lavoro

Location: Valencia, Spain, Hybrid OR Remote across EMEA
Employment: Full-Time Contract
Duration: 6 months, with potential extension
Language: Fluent English required
Industry: Cybersecurity / Cloud / Enterprise Security

About the Opportunity

Pragmatike is recruiting on behalf of a major international organization for a Security Operations Analyst to join a global Cybersecurity Operations team.

You’ll be part of a 24/7 Security Operations Centre (SOC) responsible for monitoring, detecting, investigating, and responding to cyber threats across enterprise, cloud, network, and endpoint environments.

This is a hands‑on security role focused on alert triage, threat investigation, log analysis, incident response, and security monitoring, working alongside cybersecurity specialists distributed across multiple regions.

What You’ll Do
  • Monitor, triage, and investigate security alerts across SIEM, EDR, Microsoft security tools, and cloud platforms.

  • Analyze host and network logs from Windows, Linux, databases, applications, web servers, firewalls, and NIDS/HIDS.

  • Investigate suspicious activity, identify root causes, and determine appropriate remediation or escalation.

  • Support incident response, remediation, and recovery activities.

  • Work closely with Incident Response and other cybersecurity teams to manage security threats.

  • Analyze network and security events using TCP/IP, syslog, firewall, and network monitoring data.

  • Identify opportunities to improve detection quality and reduce false positives through tuning and optimization.

  • Gather technical information from clients to improve security monitoring and detection.

  • Prepare and present security reports, summaries, and technical findings.

  • Contribute to SOC procedures, documentation, knowledge bases, and quality-control processes.

  • Review operational feedback and implement corrective actions to continuously improve service quality.

What We’re Looking For
  • 5+ years of relevant experience in IT/cybersecurity, including security alert triage and incident support.

  • Hands‑on experience working in a SOC environment.

  • Strong experience with SIEM and EDR platforms.

  • Advanced log analysis skills across Windows/Linux, databases, applications, and infrastructure.

  • Strong knowledge of Microsoft Security technologies, including Microsoft Sentinel and Defender.

  • Experience with cloud security across Azure, AWS, and/or GCP.

  • Experience with SIEM platforms such as Splunk, QRadar, ArcSight, Microsoft Sentinel, or ELK.

  • Experience with at least one EDR solution such as Microsoft Defender for Endpoint or CrowdStrike.

  • Knowledge of email security, network monitoring, and incident response.

  • Strong knowledge of Linux, macOS, and Windows.

  • Fluent English with excellent written and verbal communication skills.

Nice to Have
  • Experience working on an Incident Response team with Tier-1/Tier-2 incident triage.

  • AWS security monitoring experience across IaaS, PaaS, or SaaS environments.

  • Scripting experience with Python, PowerShell, Bash, Ruby, or similar.

  • Certifications such as Microsoft SC-200, GCIH, CEH, GCFA, GIAC, CCNA, or MCSE.

  • Customer‑facing cybersecurity experience.

Why Join
  • Work inside a global 24/7 cybersecurity operation protecting international organizations.

  • Gain exposure to large‑scale cloud, SIEM, EDR, network, and endpoint security environments.

  • Collaborate with cybersecurity specialists across multiple regions and disciplines.

  • Work directly on real‑world threat detection and incident response.

  • Build experience across a broad enterprise security technology stack.

Pragmatike is committed to a fair, transparent, and inclusive recruitment process. We do not discriminate based on age, disability, gender, gender identity or expression, marital or civil partner status, pregnancy or maternity, race, religion or belief, sex, or sexual orientation.

In accordance with GDPR, your personal data will be processed lawfully, fairly, and securely and used solely for recruitment purposes, including sharing it with our client(s) for employment consideration.

Ottieni la revisione del curriculum gratis e riservata.

o trascina qui il file.

Similar jobs

Offerte di lavoro simili che vale la pena confrontare

Senior SOC Analyst: 24/7 Cloud & Endpoint Defense (Remote)
Senior SOC Analyst: 24/7 Cloud & Endpoint Defense (Remote)

Pragmatike • Puglia

Ibrido
EUR 70.000 - 110.000
Principal Security & Detection Engineer
Principal Security & Detection Engineer

Integrity360 • Roma

Ibrido
EUR 90.000 - 130.000
Hybrid work arrangement
Application Support Technician
Application Support Technician

Pragmatike • Brindisi

Ibrido
EUR 30.000 - 42.000
CyberSecurity Specialist
CyberSecurity Specialist

K2 Partnering Solutions • Milano

In loco
EUR 60.000 - 90.000
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Arsenalia • Mestre

Ibrido
EUR 35.000 - 50.000
Corporate welfare platform
Work-life kit
Engagement initiatives
+1
Cybersecurity Operations Engineer (Europe 100% remote)
Cybersecurity Operations Engineer (Europe 100% remote)

UBQ.io • Italia

In loco
EUR 70.000 - 90.000
Cyber Security Specialist
Cyber Security Specialist

Volkswagen Group Italia S.p.A. • Verona

Ibrido
EUR 48.000 - 56.000
Remote work up to 8 days/mo
Bonuses based on performance
Cafeteria and meal options
+1
Cyber Security Specialist
Cyber Security Specialist

Volkswagen Group Italia S.P.A. • Bardi

Ibrido
EUR 48.000 - 56.000
Remote work up to 8 days per month
Free company cafeteria
Health insurance through Fondo Est and
+2
Senior Threat Intelligence Researcher at SentinelOne
Senior Threat Intelligence Researcher at SentinelOne

SentinelOne, Inc. • Milano

In loco
EUR 90.000 - 130.000
Equity & RSUs
ESPP
Time Off & Wellbeing
+6
Professional Services Principal Consultant - Incident Response, French-Speaking (Remote)
Professional Services Principal Consultant - Incident Response, French-Speaking (Remote)

CrowdStrike • Milano

Ibrido
EUR 61.000 - 95.000
Market-leading compensation
Comprehensive wellness programs
Generous vacation and holidays
+2