Security Operations Analyst (Cyber Defense Operations)

Trigyn Technologies Limited

United States

Remote

EUR 70,000 - 110,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Trigyn Technologies Limited seeks a Security Operations Analyst (Cyber Defense Operations) to join the 24x7 CSOC in a remote capacity. The role involves monitoring, triage, investigation, and response to cyber threats for partners worldwide, collaborating with cybersecurity experts.

The incumbent will analyze alerts from Microsoft security tools, AWS, SIEM/EDR, and will contribute to incident response, threat management, and reporting. Fluent English is required.

Qualifications

  • 5+ years in IT with alert triage and security incidents.
  • Experience with SIEM/EDR tools and autonomous threat analysis.
  • Trouble ticket generation and processing experience.
  • Expert knowledge of Windows, Linux, DBs and Web server logs.
  • TCP/IP protocol knowledge essential.
  • Deep knowledge of Microsoft security tools and cloud platforms.
  • Experience with Azure, AWS, GCP and Splunk/QRadar/ArcSight.
  • Knowledge of at least one EDR solution such as Defender for Endpoint or CrowdStrike.
  • Familiar with email security, network monitoring and incident response.
  • Fluent English, written and spoken.

Responsibilities

  • Monitor, triage and investigate alerts across security tools and SIEM/EDR platforms.
  • Analyze network and host logs to determine remediation steps and escalation.
  • Identify root causes and support incident response and containment.
  • Prepare security reports, summaries and client-facing findings.
  • Contribute to CSOC process improvements and knowledge base updates.

Skills

SOC tooling
Threat analysis
Incident response
Log analysis
TCP/IP knowledge
Cloud security

Tools

Splunk
QRadar
ArcSight
MS Sentinel
ELK Stack
EDR (Defender for Endpoint)

Job description

Trigyn has a contractual opportunity for a Security Operations Analyst (Cyber Defense Operations). This resource will be working remotely.

Required Profile

The incumbent will be part of the Cybersecurity Operations Section (CSO) to provide front line support to client Partners in the area of information/cyber security, risk management consulting, and security operations activities in collaboration with a team of information and cyber security experts. The resource will be part of the 24x7 Security Operations Centre (CSOC) and will work in close collaboration with team members distributed around the globe to monitor, detect, triage, investigate and respond to cyber threats targeting client or its Clients and Partner Organizations.

Scope of Work / Duties of Consultant

Reporting to the CSOC Team Lead, the incumbent will conduct the following duties and deliverables:

  • Monitor, triage, and investigate alerts across Microsoft security tools, AWS, SIEM platforms, and EDR solutions
  • Analyze network and host-based logs (firewalls, NIDS/HIDS, syslog, etc.) to determine appropriate remediation and escalation
  • Identify root causes, direct remediation and recovery actions, and support incident response efforts
  • Follow structured analytical processes and collaborate with other analysts and teams to ensure effective threat management
  • Prepare and present security reports, summaries, and findings to clients
  • Contribute to the improvement of CSOC processes and procedures, including quality control procedures, documentation and knowledge base updates
  • Gather the necessary information from the client to identify opportunities for whitelist tuning and optimization to reduce false positives and enhance detection quality
  • Reviewing feedback and implementing corrective actions to maintain service excellence
  • Provide other ad hoc support as required
The resource MUST have the following skills and experience
  • A minimum of five (5) years of relevant experience in information technology field, including triage of alerts and supporting security incidents
  • Proven experience with the usual toolbox available in a SOC (e.g., SIEMs, EDRs), able to autonomously perform technical analysis of security threats and collaborate with Incident Response team
  • Trouble ticket generation and processing experience
  • Expert knowledge of Windows, Linux, Database, Application, Web server, etc. log analysis
  • Knowledge of Transmission Control Protocol / Internet Protocol (TCP/IP) protocols
  • Deep knowledge of Microsoft Security Tools (e.g. M365, Cloud App Security, Azure, Defender for Endpoints, Azure Security, Azure Sentinel and XDR
  • Deep knowledge of Cloud technologies (e.g. Azure, AWS and GCP)
  • Deep knowledge of SIEM tools like Splunk, QRadar, ArcSight, MS Sentinel, ELK Stack
  • Knowledge of at least one EDR solution (MS Defender for Endpoint, CrowdStrike)
  • Knowledge of email security, network monitoring, and incident response
  • Knowledge of Linux/Mac/Windows
  • Expert knowledge of English, both written and spoken, is required
The resource SHOULD have the following skills and experience

Experience on an Incident Response team performing Tier I/II initial incident triage.

Proven knowledge of monitoring AWS environment (Iaas, Saas, Paas)

Knowledge of at least one general-purpose or shell scripting language (e.g. Ruby, Bash, PowerShell, Python, etc.)

Required Soft Skills
  • Excellent communication skills
  • Customer-facing experience and oral communication skills
  • Ability to write documentation & reports
  • Creativity/ ability to find innovative solutions
  • Willingness to learn on the jobConflict management & cooperation
Desirable certifications
  • Technical certifications: MCSE, CCNA, Microsoft Azure (e.g., SC-200), GCIH, CEH, GCFA or any GIAC/similar certification
  • Relevant industry certifications

TRIGYN TECHNOLOGIES is a multinational IT services company with resources deployed in 28 countries. TRIGYN is an ISO 9001:2015, ISO 27001:2022 (ISMS) and CMMI Level 5 certified company. TRIGYN has offices in the United States, Canada, Switzerland and India.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote Cyber Defense Security Operations Analyst
Remote Cyber Defense Security Operations Analyst

Trigyn Technologies Limited • United States

Remote
EUR 70,000 - 110,000
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

TriCom Technical Services • Saint Paul (MN)

Hybrid
USD 70,000 - 110,000
Contract position
401(k) match
Paid time off
+1
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Cyber Triage Analyst
Cyber Triage Analyst

NewGen Technologies • Arlington (VA)

On-site
USD 90,000 - 130,000
Network Security Analyst
Network Security Analyst

vTech Solution • Washington

On-site
USD 75,000 - 110,000
Analyst, Cyber Security II
Analyst, Cyber Security II

TALENT Software Services • Columbia (SC)

On-site
USD 90,000 - 140,000
Cyber Security Analyst
Cyber Security Analyst

Clinisoltech • Huntsville (AL)

Hybrid
USD 80,000 - 90,000
Sr. Cyber Triage Analyst
Sr. Cyber Triage Analyst

NewGen Technologies • Arlington (VA)

On-site
USD 140,000 - 190,000
Security Operations Engineer — Hybrid, Incident Response
Security Operations Engineer — Hybrid, Incident Response

Trean Corporation • Wayzata (MN)

Hybrid
USD 85,000 - 110,000
Senior SIEM & Threat Detection Analyst (Remote)
Senior SIEM & Threat Detection Analyst (Remote)

Trigyn Technologies Limited • United States

Remote
USD 90,000 - 130,000