Security Operations Analyst (L1)

Greenhouse Software, Inc.

United States

Remote

USD 65,000 - 90,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

20 paid vacation days per year
10 paid sick leave days per year
Public holidays as per company policy
Medical budget
Opportunity to work remotely
Professional education budget
Language learning budget
Wellness budget

Job summary

JustMarkets, a fast-growing fintech company in the United States, is seeking a Security Operations Analyst to join as a full-time team member. You will monitor alert queues, triage incidents, and document findings to support rapid response.

Candidates should have hands-on SIEM experience, knowledge of EDR/XDR, and the ability to correlate data across endpoints, networks, and cloud services. The role offers remote work options and budget for professional education.

Qualifications

  • Hands-on experience with security alert triage using at least one SIEM and EDR/XDR.
  • Ability to build basic searches and correlate events across data sources (KQL/EQL).
  • Interpret telemetry from endpoints, identity, network, cloud audits and services.
  • Fundamentals of Windows, Linux, TCP/IP, DNS, HTTP, and authentication.
  • Distinguish true vs. false positives; assign preliminary severity.
  • Awareness of MITRE ATT&CK framework and threat intel relevance.
  • Document evidence, actions and handover notes in a case-management system.

Responsibilities

  • Monitor prioritized alert queues and validate whether alerts indicate real risk.
  • Enrich cases and correlate relevant endpoint, identity, authentication, network, service, asset, user, timeline, and business context.
  • Perform initial investigations, classify alerts, assess preliminary severity and scope, and document the evidence and reasoning in the case-management system.
  • Close false positives and execute approved low-risk actions only through defined runbooks.
  • Escalate suspected incidents, privileged-account issues, and high-impact or production-impact cases to L2, the manager, or Incident Response.
  • Maintain clear handover notes and support improvements to case quality and runbooks.

Skills

Security alert triage
SIEM experience
KQL/EQL queries
Endpoint & network telemetry
Windows & Linux basics
Threat intel awareness
Investigation timelines
Runbooks adherence

Tools

Case-management system

Job description

We are inviting you, a highly motivated and results-oriented Security Operations Analyst to join our team on a full-time basis.

Our team has unique expertise in research, analysis, and product development. By relying on technical insights and a data-driven approach, we create disruptive future-defining innovations of the fin-tech industry that remain our basis for success.

Responsibilities
  • Monitor prioritized alert queues and validate whether alerts indicate real risk
  • Enrich cases and correlate relevant endpoint, identity, authentication, network, service, asset, user, timeline, and business context
  • Perform initial investigations, classify alerts, assess preliminary severity and scope, and document the evidence and reasoning in the case-management system
  • Close false positives and execute approved low-risk actions only through defined runbooks
  • Escalate suspected incidents, privileged-account issues, and high-impact or production-impact cases to L2, the manager, or Incident Response
  • Maintain clear handover notes and support improvements to case quality and runbooks
Requirements
  • Hands-on experience with security alert triage through work, an internship, or a practical lab, including use of at least one SIEM and exposure to EDR or XDR and case-management workflows
  • Ability to build basic searches or queries, filter security events, and correlate related activity across more than one data source (Experience with basic SIEM query languages such as KQL, EQL)
  • Ability to interpret common endpoint, identity, authentication, network, DNS, HTTP, and service or cloud audit telemetry at an initial-investigation level
  • Working fundamentals of Windows and Linux, TCP/IP, DNS, HTTP, authentication, access control, and common attack patterns such as phishing, credential abuse, malware execution, and suspicious account activity
  • Ability to distinguish true positives, false positives, and benign activity; assign a preliminary severity; identify affected users or assets; and recognize when scope or impact is uncertain
  • Basic use of indicators of compromise, reputation sources, and threat-intelligence context, with awareness of the MITRE ATT&CK framework
  • Ability to create a concise investigation timeline and document evidence, actions, conclusions, and handover or escalation notes in a case-management system
  • Ability to follow approved runbooks, perform only authorized low-risk actions, recognize the limits of L1 authority, and elevate suspected incidents correctly
Will be a plus
  • Simple Python or PowerShell scripts for investigation and enrichment
  • Exposure to cloud, email-security, or SaaS audit logs and common phishing-investigation workflows
  • Practical cybersecurity labs or an entry-level certification such as Security+ or CySA+
  • Experience with MacOS
We offer
  • 20 paid vacation days per year
  • 10 paid sick leave days per year
  • Public holidays as per the company's approved Public holiday list
  • Medical budget
  • Opportunity to work remotely
  • Professional education budget
  • Language learning budget
  • Wellness budget (gym membership, sports gear and related expenses)
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

On-site
USD 97,600 - 109,800
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Incident Response & DFIR Lead
Incident Response & DFIR Lead

Greenhouse Software, Inc. • United States

Remote
USD 120,000 - 210,000
Vacation days
Sick leave
Public holidays
+5
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Staff CSIRT Analyst
Staff CSIRT Analyst

Hidden Jobs • United States

Remote
USD 180,000 - 240,000
Remote US-wide
Generous paid time off
Medical, dental & vision benefits
+4
L1 Cyber Security Analyst
L1 Cyber Security Analyst

SPHYNX Group • Kentucky

On-site
USD 70,000 - 100,000
Senior Detection and Response Analyst
Senior Detection and Response Analyst

Prestige Staffing • Dallas (TX)

On-site
USD 120,000 - 180,000
Contract extension potential
Remote work
Career growth
+2
L3 Security Analyst
L3 Security Analyst

Sphynx • Town of Greece (NY)

On-site
USD 110,000 - 165,000
Competitive remuneration
Excellent conditions
Professional development
+1
Security Analyst I
Security Analyst I

ABC Legal Services • Seattle (WA)

Hybrid
USD 90,000 - 105,000
Health insurance
Dental insurance
Vision insurance
+5
Information Security Analyst
Information Security Analyst

Cisive • Maryland

On-site
USD 80,000 - 110,000
Senior Security Operations Analyst III
Senior Security Operations Analyst III

clear • New York (NY)

On-site
USD 120,000 - 180,000
Catered lunches
Wellness stipend
Healthcare plans
+2