Remotely
siemsplunkedrmitre att&ckcrowdstrikesoarmicrosoft sentineldefender
Job Description
📋 Description
- Own the full incident lifecycle during non-US hours — from initial triage through containment
- Conduct in-depth investigation of security events across SIEM, EDR, email security, network
- Perform root cause analysis on confirmed incidents and produce clear, actionable incident reports
- Escalate incidents with concise situation summaries and recommended actions to leadership
- Develop, maintain, and improve incident response playbooks and SOC runbooks
- Provide detailed shift handoff notes to ensure continuity of investigations
🎯 Requirements
- Bachelor's degree in Computer Science, IT, Electronics, or related field
- 4–6 years of experience in SOC or cybersecurity operations
- Hands-on experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel, IBM QRadar)
- Strong knowledge of EDR tools (CrowdStrike, Defender, SentinelOne) and MITRE ATT&CK
- Experience with SOAR platforms and alert automation; basic scripting (Python, PowerShell)
- Advanced log analysis across Windows, Linux, cloud (AWS/Azure/GCP) and identity (AD/Azure AD)
🎁 Benefits
- Hybrid/shift-based overlap with US team; comfortable working non-US business hours
- Excellent comprehensive benefits and opportunities to grow in security leadership
Back to all jobs