Overview
Cyber Security Operations Engineer responsible for executing complex cybersecurity operations and incident response to protect systems and networks from advanced threats. The role includes operating enterprise security services such as continuous cyber operations, incident response, monitoring, threat hunting, and digital forensics, and using security tools (SIEM, EDR, Email Security Gateway with focus on CrowdStrike Falcon XDR) to investigate, correlate, and analyze suspicious events.
Responsibilities
- Execute complex cybersecurity operations and incident response to protect systems and networks from advanced threats.
- Operate enterprise security services such as continuous cyber operations, incident response, monitoring, threat hunting, and digital forensics.
- Use security tools (SIEM, EDR, Email Security Gateway—focus on CrowdStrike Falcon XDR) to investigate, correlate, and analyze suspicious events.
- Perform proactive and reactive threat hunting and cyber threat analysis.
- Ensure security controls are developed, managed, and maintained.
- Support business impact analysis and recommend appropriate security measures for information assets.
- Participate in incident response activities, including supporting major incidents and internal drills.
- Collaborate with cross-functional teams; provide expert guidance and mentorship to junior analysts.
- Participate in on-call rotation (including weekends) for continuous operations.
- Prepare regular updates and recommend modifications to improve security systems and procedures.
- Translate complex technical issues into simple, understandable concepts in written English.
Qualifications
- Degree in Cybersecurity, Risk Analysis, Computer Science, Information Systems, or related field, or equivalent work experience.
- 2-4 years of combined IT and cybersecurity experience.
- Hands-on experience with cybersecurity investigations and EDR tools.
- Understanding of industry frameworks (MITRE ATT&CK, D3FEND, NIST, Cyber Kill Chain).
- Strong written communication skills.
- Experience supporting incident response and EDR detection/response.
Preferred Qualifications
- Multilingual (Turkish, Spanish, French, Lithuanian).
- Security certifications (CompTIA Security+, CySA+, CEH, or equivalent).
- Expertise in Digital Forensics or Threat Hunting.
- Scripting skills (Python, PowerShell, Bash).
- Experience developing detection rules and SOAR playbooks.
Details
- Seniority level: Mid-Senior level
- Employment type: Full-time
- Job function: Information Technology
- Industries: Information Services