Security Analyst Remote.
We are is seeking a Security Analyst with hands-on experience monitoring and analyzing security alerts within EDR/SIEM environments. You will join our DRTI Team, contributing to our MDR (Managed Detection and Response) and MTI (Managed Threat Intelligence) services.
This role involves deep threat investigations, applying threat intelligence, executing mitigation actions, and actively supporting the continuous improvement of detection processes and capabilities. You will work in a highly technical, international, and collaborative environment.
Responsibilities
- Monitor and analyze security alerts in EDR/SIEM platforms, identifying suspicious activity and performing initial triage.
- Investigate threats using threat intelligence to anticipate potential attacks.
- Execute containment and mitigation actions to minimize incident impact.
- Create reports and notifications including findings, conclusions, and recommendations for clients.
- Optimize detection rules and reduce false positives.
- Contribute to improving procedures, playbooks, and workflows.
- Automate tasks using PowerShell, Python, or Bash scripting.
- Participate in client meetings for alert reviews, follow-up, and initial deployment support.
Qualifications
- Bachelor's degree in Engineering, Cybersecurity, or equivalent education/experience.
- At least 2 years of experience analyzing alerts in SIEM/EDR platforms (CrowdStrike, Sentinel, Cortex, Splunk, ELK, LogRhythm, QRadar, Chronicle, Wazuh, etc.).
- Knowledge of Windows and UNIX/Linux system administration.
- Strong understanding of networks and protocols (TCP/IP, DHCP, DNS, etc.).
- Scripting skills (Bash, Python, PowerShell).
- Strong analytical and problem-solving skills to correlate events and detect patterns.
- Attention to detail, critical thinking, and a proactive mindset.
- Solid organizational and teamwork skills.
Skills
- EDR/SIEM Alert Monitoring & Analysis
- Threat Intelligence
- Incident Response
- Scripting (PowerShell, Python, Bash)
- Networking & Protocols
- Windows and Linux Administration
- Technical Reporting
- Detection Rule Optimization
- Teamwork & Effective Communication
- English C1
Requirements
- Degree: Engineering, Cybersecurity, or equivalent experience.