We are looking for a Security Operations (SOC) Analyst to strengthen security monitoring, incident response, and detection engineering across a SOC environment. You will triage alerts, hunt threats, improve SOC/SOAR workflows, and communicate findings through clear reporting—apply now to help raise our security posture.ResponsibilitiesRespond to security incidents and coordinate appropriate containment and remediation actionsTriage, investigate, and prioritize security alerts across the SOC toolsetDevelop and tune rule sets and use cases to improve detection quality and reduce false positivesHunt for threats and support threat intelligence processes, including mapping to TTPsUse advanced analytic tools to identify emerging threat patterns and vulnerabilitiesImprove SOC/SOAR tooling, workflows, and automation to raise efficiency and coverageGenerate clear reports for various stakeholders and communicate findings effectivelyPlan and run SOC tabletop exercises to validate readiness and response proceduresParticipate in the on-call rotation every 8th weekendRequirements2+ years of experience in Security Operation Center (SOC) operations and security monitoring2+ years of experience with SIEM and endpoint security tools such as Splunk and Microsoft DefenderStrong incident response skills and alert triage capabilitySolid use case development skills for rule sets and detection logicGood knowledge of malware detection and intrusion detection and prevention systems (IDPS)Strong understanding of Windows, Linux, database, and network device monitoring and logging techniquesGood understanding of host and network security hardening, networking protocols, common intrusion techniques, and risk management conceptsStrong analytical skills to identify emerging threat patterns and vulnerabilities using advanced analyticsHigh attention to detail and strong logical thinkingCurious mindset and confidence to ask questions when neededUpper-Intermediate English proficiency (B2)Availability for on-call duty every 8th weekendNice to haveTanium experience or exposure to asset management, patch management, and EDR solutionsQualys experienceAzure Sentinel experienceAWS security experienceServiceNow SecOps experienceWe offerInternational projects with top brandsWork with global teams of highly skilled, diverse peersHealthcare benefitsEmployee financial programsPaid time off and sick leaveUpskilling, reskilling and certification coursesUnlimited access to the LinkedIn Learning library and 22,000+ coursesGlobal career opportunitiesVolunteer and community involvement opportunitiesEPAM Employee GroupsAward-winning culture recognized by Glassdoor, Newsweek and LinkedInEPAM is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, sexual orientation, gender identity or expression, disability, protected veteran status, or any other characteristic protected by applicable law.