Security Operations Analyst (SIEM Operations and Threat Detection)

SmartRecruiters, Inc.

Warszawa

Remote

PLN 184,000 - 306,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Remote position
Training & career development
Multicultural team

Job summary

Talan Spain is seeking a Security Operations Analyst to strengthen threat detection and CSOC capabilities in a globally distributed team. You will drive security content management, validation of detection mechanisms, and onboarding of new data sources for SIEM, EDR, and cloud platforms.

You will participate in use-case lifecycle management, tuning, and content quality assurance while collaborating with incident response and threat intelligence teams to improve monitoring and reporting across

Qualifications

  • Minimum 5 years in information technology or security operations.
  • Experience administering SIEM platforms (Splunk or MS Sentinel preferred).
  • Hands-on with SOC tools (SIEM, EDR) and threat analysis.
  • Knowledge of Microsoft security tools and cloud platforms.
  • Experience building detections and tuning false positives.
  • Ability to document findings and produce reports.

Responsibilities

  • Develop, validate, tune, and maintain security monitoring and detection.
  • Operate and improve threat detection services across SIEM/EDR/cloud.
  • Onboard and validate security data sources and telemetry feeds.
  • Manage use-case lifecycle, rules reviews, and content QA.
  • Collaborate with threat intel, IR, and security operations teams.
  • Support architecture reviews and enhance monitoring effectiveness.
  • Prepare security metrics, dashboards, and KPI reports.
  • Review detections and configurations for quality and gaps.
  • Gather feedback to tune detections and reduce false positives.
  • Create CSOC procedures and knowledge base materials.
  • Prepare technical reports and present findings to stakeholders.

Skills

SIEM administration
Threat detection
Incident response
Linux/Windows
Cloud knowledge
Security analytics
Documentation

Tools

Splunk
MS Sentinel
QRadar
ELK Stack
EDR tools
PowerShell

Job description

Security Operations Analyst (SIEM Operations and Threat Detection)
  • Full-time
  • Contract Type: Long term contract

Talan is an international consulting group specializing in innovation and business transformation through technology. With over 7,200 consultantsin 21 countriesand a turnover of €850M, we are committed to delivering impactful, future-ready solutions.

Talan at a Glance

Headquartered in Paris and operating globally, Talan combines technology, innovation, and empowermentto deliver measurable results for our clients. Over the past 22 years, we’ve built a strong presence in the IT and consulting landscape, and we’re on track to reach €1 billion in revenuethis year.

Our Core Areas of Expertise

  • Data & Technologies: We design and implement large-scale, end-to-end architecture and data solutions, including data integration, data science, visualization, Big Data, AI, and Generative AI.
  • Cloud & Application Services: We integrate leading platforms such as SAP, Salesforce, Oracle, Microsoft, AWS, and IBM Maximo, helping clients transition to the cloud and improve operational efficiency.
  • Management & Innovation Consulting: We lead business and digital transformation initiativesthrough project and change management best practices (PM, PMO, Agile, Scrum, Product Ownership), and support domains such as Supply Chain, Cybersecurity, and ESG/Low-Carbon strategies.

We work with major global clients across diverse sectors, including Transport & Logistics, Financial Services, Energy & Utilities, Retail, and Media & Telecommunications.

We are looking to join a Senior consultant within the Cyber Security Operations Center (CSOC), a globally distributed team of cybersecurity professionals responsible for protecting complex and diverse technology environments.

The role is primarily focused on enhancing threat detection and cybersecurity operations capabilities through activities such as security content management, quality assurance and validation of detection mechanisms, detection use case lifecycle management, onboarding and integration of new security data sources, reporting, and process optimization.

This is an excellent opportunity for professionals interested in working within a large-scale international cybersecurity environment, where they will play a key role in the continuous improvement of security monitoring and threat detection services across multiple customer landscapes. The position combines elements of Security Operations, Threat Detection Engineering, SIEM optimization, cyber risk management, and operational excellence, offering exposure to a wide variety of cybersecurity technologies and challenges.

Main Responsibilities:

  • Contribute to the development, implementation, validation, tuning, and maintenance of security monitoring, analytics, and detection capabilities across SIEM, EDR, cloud, and other cybersecurity platforms.
  • Support the operation, maintenance, optimization, and continuous improvement of security monitoring and threat detection services.
  • Participate in the onboarding, integration, testing, and validation of security data sources, telemetry feeds, and monitoring capabilities.
  • Contribute to security content management activities, including use case lifecycle management, rule reviews, testing, tuning, and content quality assurance.
  • Collaborate with cyber threat intelligence, incident response, and cybersecurityoperations teams to translate operational and threat intelligence requirements into effective detection and monitoring capabilities.
  • Under guidance, participate in cybersecurity architecture reviews of new or existing solutions and provide recommendations to enhance security monitoring and detection effectiveness.
  • Contribute to the preparation and maintenance of cybersecurity operations metrics, dashboards, KPIs, and service performance reports.
  • Review, validate, and assess the effectiveness of detections, monitoring configurations, operational processes, and service deliverables, identifying opportunities for improvement.
  • Gather and analyze operational feedback to identify opportunities for tuning, optimization, reduction of false positives, and improvement of overall detection quality.
  • Contribute to quality assurance activities, including process reviews, control validation, service quality assessments, and implementation of corrective actions.
  • Support the development, review, and maintenance of CSOC procedures, standards,documentation, knowledge base articles, and operational guidance materials.
  • Prepare and present technical reports, summaries, findings, and recommendations to internal and external stakeholders.

On-Call Availability (On-Call Shift System)

Mandatory 24/7 On-Call Rotation: You will be required to participate in a rotating on-call shift schedule from Monday to Sunday.

What this means: This does not mean you will be actively working 24/7 or during late-night shifts. Instead, you will be on standby outside of standard working hours, meaning you must be reachable and available to log in and resolve critical system incidents only if they arise.

Frequency: The approximate rotation frequency is one full week (7 consecutive days) every X months, depending on the number of team members

Must have:

  • +5 years of relevant experience in information technology field, including triage of alerts and supporting security incidents
  • Proven experience on administering a SIEM platform, preferably either Splunk or Microsoft Sentinel SIEM
  • Proven experience with the usual toolbox available in a SOC (e.g., SIEMs, EDRs) and being able to autonomously perform technical analysis of security threats and collaborate with Incident Response team
  • Deep knowledge of Microsoft Security Tools (e.g. M365, Cloud App Security, Azure, Defender for Endpoints, Azure Security, Azure Sentinel and XDR)
  • Deep Knowledge of Cloud technologies (e.g. Azure, AWS and GCP)
  • Deep knowledge of SIEM tools like Splunk, QRadar, ArcSight, MS Sentinel, ELK Stac
  • Knowledge of at least one EDR solution (MS Defender for Endpoint, CrowdStrike)
  • Knowledge of email security, network monitoring, and incident response
  • Knowledge of Linux/Mac/Windows

Nice to have:

  • Experience in building SIEM architectures from initial design to implementation, including designing data ingestion pipelines for diverse log sources across cloud and on-prem environments
  • Knowledge of at least one general-purpose or shell scripting language (e.g. Ruby, Bash, PowerShell, Python, etc.)

Desirable certifications:

  • MCSE, CCNA, Microsoft Azure (e.g., SC-200), GCIH, CEH, GCFA or any GIAC/similar certification

Required Soft Skills:

  • Customer-facing experience and oral communication skills
  • Ability to write documentation & reports
  • Creativity/ ability to find innovative solutionsWillingness to learn on the job
  • Conflict management & cooperation

What do we offer you?

  • Remote Position
  • Freelance, full-time contract.
  • Training and career development.
  • Possibility to be part of a multicultural team and work on international projects.

If you are passionate about data, development & tech, we want to meet you!

Talan Spain’s commitment to non-discrimination based on gender, race, ideology, or any other reason, in accordance with the company’s "Equality Plan" and the current regulations on gender equality between women and men (Royal Decree-Law 6/2019).

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations Analyst (SIEM Operations and Threat Detection)
Security Operations Analyst (SIEM Operations and Threat Detection)

Talan • Warszawa

Hybrid
PLN 306,000 - 481,000
Remote Position
Training and career development
International projects
+1
Remote SIEM Operations & Threat Detection Analyst
Remote SIEM Operations & Threat Detection Analyst

SmartRecruiters, Inc. • Warszawa

Remote
PLN 184,000 - 306,000
Remote position
Training & career development
Multicultural team
Senior SIEM Threat Detection & Security Ops Specialist
Senior SIEM Threat Detection & Security Ops Specialist

Talan • Warszawa

Hybrid
PLN 306,000 - 481,000
Remote Position
Training and career development
International projects
+1
Remote Cybersecurity Architect: SIEM & SOC Lead (German)
Remote Cybersecurity Architect: SIEM & SOC Lead (German)

Experis ManpowerGroup Sp. z o.o. • Poland

On-site
PLN 180,000 - 240,000
Cyber Security Architect
Cyber Security Architect

Experis ManpowerGroup Sp. z o.o. • Poland

Remote
PLN 180,000 - 240,000
Multisport Card
Life insurance
Private healthcare
+1
Cyber Security Architect
Cyber Security Architect

Experis ManpowerGroup Sp. z o.o. • Warszawa

On-site
PLN 180,000 - 300,000
Multisport Card
Life insurance
Private healthcare
+1
Lead Security Operations Engineer
Lead Security Operations Engineer

Jobtailor • Wrocław

On-site
PLN 180,000 - 240,000
SOC Analyst (L1/L2)
SOC Analyst (L1/L2)

UnderDefense LLC • Warszawa

On-site
PLN 120,000 - 180,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Talan Group • Warszawa

On-site
PLN 210,526 - 315,789
Private medical insurance
Life insurance
Training and career development
+1
Junior Data Engineer
Junior Data Engineer

Talan Group • Warszawa

On-site
PLN 120,000 - 180,000
Private medical insurance
Life insurance
Training and career development
+3