Monitor enterprise security alerts and investigate, prioritize, and respond to threats across SIEM, EDR, network, and cloud telemetry. Contain active compromises, tune detection rules, automate response playbooks, conduct malware analysis and threat hunting, and document post-incident findings using the MITRE ATT&CK framework.
This is a remote position.
Security Operations Center (SOC) Analyst / Engineer
Job Details
Employment Type: Contract
Work Mode: Remote
Location: Offshore
Total Experience Required: 4 to 7 years
Relevant Experience Required: 3+ years of dedicated experience working within a 24/7 SOC environment running threat detection and incident response
Mandatory Certification: Certified Information Systems Security Professional (CISSP), CompTIA Security+, CEH (Certified Ethical Hacker), or GIAC Certified Incident Handler (GCIH)
Job Summary
We are seeking an experienced SOC Analyst / Engineer to monitor, detect, analyze, and respond to cyber threats across our global enterprise infrastructure. The ideal candidate will orchestrate real-time security incident monitoring using advanced SIEM/SOAR platforms, perform deep technical analysis of anomalous events, and execute rapid containment workflows to safeguard business networks.
Key Responsibilities
Monitor real-time enterprise security alerts across a multi-tenant infrastructure, parsing telemetry data from SIEM, EDR, firewalls, network sensors, and cloud logs.
Lead incident triage and analysis tracks, investigating anomalous events, identifying true positives, and prioritizing security alerts based on risk and operational impact.
Execute rapid threat containment workflows, neutralizing live compromises, isolating infected endpoints, disabling compromised accounts, and revoking unauthorized access tokens.
Configure and tune SIEM correlation rules (e.g., Splunk, Microsoft Sentinel) to enhance detection accuracy and systematically eliminate noise and false positives.
Develop and automate SOAR playbooks (e.g., Palo Alto Cortex XSOAR, Splunk SOAR) to streamline recurring incident response actions and shorten mean time to remediate (MTTR).
Perform detailed malware analysis and threat hunting sweeps, evaluating suspicious files, malicious scripts, phishing vectors, and indicators of compromise (IOCs).
Document and report post-incident reviews, mapping threat behaviors directly to the MITRE ATT&CK framework, identifying detection gaps, and tracking infrastructure remediation needs.
Requirements
4 to 7 years of core IT systems security experience, with 3+ dedicated years actively executing real-time threat detection and incident response in a mature SOC.
Strong technical mastery of enterprise SIEM environments, Endpoint Detection and Response tools (EDR/XDR like CrowdStrike, Defender for Endpoint), and packet capture analysis software (Wireshark).
Deep structural understanding of network architecture, TCP/IP protocols, common attack vectors, application vulnerabilities, and modern operating system security.
Mandatory certification: Security+, CEH, GCIH, or CISSP.
Preferred Qualifications
Prior experience writing detection rules using KQL, YARA, or Sigma formatting rules.
Familiarity with scripting languages (Python, PowerShell) to extend custom security tool automations and log parsing logic.
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”