Security Operations Analyst (Cyber Defense Operations)

Pragmatike

United States

Hybrid

USD 53,000 - 84,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Pragmatike is recruiting for a Security Operations Analyst to join a global Cybersecurity Operations team. You’ll monitor, triage, and respond to cyber threats across enterprise, cloud, and network environments in a 24/7 SOC.

The role focuses on alert triage, incident response, log analysis, and security monitoring with specialists distributed across regions. We are looking for 5+ years of IT/cybersecurity experience, strong SIEM/EDR skills, and fluency in English.

Qualifications

  • 5+ years in IT/cybersecurity with SOC/triage experience.
  • Hands-on SOC in 24/7 environments.
  • Strong in SIEM/EDR and log analysis across Windows/Linux.
  • Proficient with Microsoft security tools (Sentinel/Defender).

Responsibilities

  • Monitor, triage, and investigate security alerts in SIEM/EDR and cloud tools.
  • Analyze logs from Windows, Linux, databases, apps, and networks.
  • Support incident response and remediation activities.
  • Prepare security reports and share technical findings.
  • Improve detection quality and reduce false positives.
  • Collaborate with Incident Response teams across regions.

Skills

SOC experience
SIEM
EDR
Log analysis
Windows/Linux
Cloud security
Microsoft Defender
English

Tools

Splunk
Microsoft Sentinel
CrowdStrike
ELK
Microsoft Defender for Endpoint
Azure
AWS
GCP
QRadar

Job description

Location: Valencia, Spain, Hybrid OR Remote across EMEA
Employment: Full-Time Contract
Duration: 6 months, with potential extension
Language: Fluent English required
Industry: Cybersecurity / Cloud / Enterprise Security

ABOUT THE OPPORTUNITY

Pragmatike is recruiting on behalf of a major international organization for a Security Operations Analyst to join a global Cybersecurity Operations team.

You’ll be part of a 24/7 Security Operations Centre (SOC) responsible for monitoring, detecting, investigating, and responding to cyber threats across enterprise, cloud, network, and endpoint environments.

This is a hands‑on security role focused on alert triage, threat investigation, log analysis, incident response, and security monitoring, working alongside cybersecurity specialists distributed across multiple regions.

WHAT YOU’LL DO
  • Monitor, triage, and investigate security alerts across SIEM, EDR, Microsoft security tools, and cloud platforms.
  • Analyze host and network logs from Windows, Linux, databases, applications, web servers, firewalls, and NIDS/HIDS.
  • Investigate suspicious activity, identify root causes, and determine appropriate remediation or escalation.
  • Support incident response, remediation, and recovery activities.
  • Work closely with Incident Response and other cybersecurity teams to manage security threats.
  • Analyze network and security events using TCP/IP, syslog, firewall, and network monitoring data.
  • Identify opportunities to improve detection quality and reduce false positives through tuning and optimization.
  • Gather technical information from clients to improve security monitoring and detection.
  • Prepare and present security reports, summaries, and technical findings.
  • Contribute to SOC procedures, documentation, knowledge bases, and quality‑control processes.
  • Review operational feedback and implement corrective actions to continuously improve service quality.
WHAT WE’RE LOOKING FOR
  • 5+ years of relevant experience in IT/cybersecurity, including security alert triage and incident support.
  • Hands‑on experience working in a SOC environment.
  • Strong experience with SIEM and EDR platforms.
  • Advanced log analysis skills across Windows/Linux, databases, applications, and infrastructure.
  • Strong knowledge of Microsoft Security technologies, including Microsoft Sentinel and Defender.
  • Experience with cloud security across Azure, AWS, and/or GCP.
  • Experience with SIEM platforms such as Splunk, QRadar, ArcSight, Microsoft Sentinel, or ELK.
  • Experience with at least one EDR solution such as Microsoft Defender for Endpoint or CrowdStrike.
  • Knowledge of email security, network monitoring, and incident response.
  • Strong knowledge of Linux, macOS, and Windows.
  • Fluent English with excellent written and verbal communication skills.
NICE TO HAVE
  • Experience working on an Incident Response team with Tier‑1/Tier‑2 incident triage.
  • AWS security monitoring experience across IaaS, PaaS, or SaaS environments.
  • Scripting experience with Python, PowerShell, Bash, Ruby, or similar.
  • Certifications such as Microsoft SC‑200, GCIH, CEH, GCFA, GIAC, CCNA, or MCSE.
  • Customer‑facing cybersecurity experience.
WHY JOIN
  • Work inside a global 24/7 cybersecurity operation protecting international organizations.
  • Gain exposure to large‑scale cloud, SIEM, EDR, network, and endpoint security environments.
  • Collaborate with cybersecurity specialists across multiple regions and disciplines.
  • Work directly on real‑world threat detection and incident response.
  • Build experience across a broad enterprise security technology stack.

Pragmatike is committed to a fair, transparent, and inclusive recruitment process. We do not discriminate based on age, disability, gender, gender identity or expression, marital or civil partner status, pregnancy or maternity, race, religion or belief, sex, or sexual orientation.

In accordance with GDPR, your personal data will be processed lawfully, fairly, and securely and used solely for recruitment purposes, including sharing it with our client(s) for employment consideration.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations Analyst (SIEM & Threat Detection)
Security Operations Analyst (SIEM & Threat Detection)

Pragmatike • United States

Hybrid
USD 80,000 - 125,000
Security Operations Analyst - 24/7 SOC | Hybrid/Remote
Security Operations Analyst - 24/7 SOC | Hybrid/Remote

Pragmatike • United States

Hybrid
USD 53,000 - 84,000
Security Operations Analyst
Security Operations Analyst

The Phoenix Group • Arlington (VA)

On-site
USD 90,000 - 120,000
SOC Analyst
SOC Analyst

Cato Networks • United States

Hybrid
USD 90,000 - 150,000
Hybrid work model
Global team collaboration
Cyber Security Analyst
Cyber Security Analyst

Synergy Business Consulting, Inc. • Tampa (FL)

On-site
USD 75,000 - 105,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Engineer, Security
Engineer, Security

11:11 Systems • United States

On-site
USD 120,000 - 160,000
Senior Threat Analyst 1
Senior Threat Analyst 1

Sophos • United States

Remote
USD 110,000 - 150,000
Remote-first
Volunteer days
Diversity networks
+2
SOC Analyst
SOC Analyst

PSG Global Solutions • Dallas (TX)

On-site
USD 90,000 - 120,000
SOC Analyst I
SOC Analyst I

SOClogix, Inc. • Catonsville (MD)

On-site
USD 55,000 - 75,000
Health insurance
Dental insurance
Vision insurance
+6