Security Operations Analyst

3 months, 1 week ago
Full-time
Junior
Cybersecurity
AlphaSense

AlphaSense

AlphaSense develops an artificial intelligence-based search platform that enables investment and corporate professionals to quickly access and analyze extensive financial data and market insights from over 500 million documents, enhancing decision-maki...

Internet Software & Services
251-1K
Founded 2011
$770M raised

Description

  • Monitor and triage security alerts across SIEM, EDR, cloud security, identity, and other platforms.
  • Perform initial investigation on escalated events by collecting and correlating evidence across log sources.
  • Execute containment and remediation actions within defined escalation thresholds.
  • Maintain accurate and timely incident documentation in the tracking system.
  • Contribute to YARA-L rule development and tuning in Chronicle/Google SecOps.
  • Assist with CrowdStrike Falcon IOA and prevention policy maintenance.
  • Review threat intelligence feeds and correlate IOCs against internal telemetry.
  • Identify detection gaps and recommend improvements to security coverage.
  • Triage cloud security findings and investigate identity anomalies such as suspicious logins and MFA bypass attempts.
  • Author and maintain SOC runbooks and triage playbooks, and participate in shift handoff knowledge transfer.

Requirements

  • 2–4 years of experience in SOC, incident response, or security operations.
  • Bachelor's degree (B. Tech) from a Tier 1 or Tier 2 institution.
  • Hands-on experience with a SIEM platform such as Chronicle, Splunk, Sentinel, or equivalent.
  • Familiarity with EDR tooling, preferably CrowdStrike Falcon.
  • Foundational understanding of cloud security concepts across AWS or GCP.
  • Working knowledge of identity threat patterns such as credential stuffing, MFA fatigue, and account takeover.
  • Ability to read and interpret authentication, network, endpoint, and cloud audit logs.
  • Strong written communication skills for clear incident documentation and escalation summaries.
  • Exposure to CSPM/CWPP platforms (preferred).
  • Scripting proficiency in Python or similar for basic automation and log parsing (preferred).
  • Relevant certifications such as CompTIA Security+, CySA+, GCIH, or GCIA (preferred).

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Associate Principal Cyber Threat Intelligence Analyst

Dragos 251-1K Professional Services

Dragos is hiring an OT Cyber Threat Intelligence Analyst to support a Singapore government security team with threat hunting, intelligence analysis, and incident response for critical infrastructure environments.

LLM SIEM
12 hours, 11 minutes ago

Security Operations Analyst II

Alphasense 51-250 Industrial Conglomerates

AlphaSense is hiring a Security Operations Analyst II to join its fully remote Security Operations team in Canada and help triage alerts, investigate incidents, and improve detection coverage.

AWS DNS GCP SIEM TCP/IP TLS
1 day, 12 hours ago

CyberSecurity Specialist

Avertium 251-1K IT Services

Avertium is hiring a Cyber Security Specialist to support 24x7 SOC monitoring and incident response for mid-market and enterprise clients.

Cybersecurity DNS Encryption HIPAA HTTP SIEM TCP/IP
1 day, 12 hours ago

Security Operations Engineer

Mesh 51-200 financial services

Mesh is hiring a Security Ops Engineer to design, operate, and respond to security controls across its infrastructure and systems as it builds payments infrastructure for the next era of the global economy.

AWS Azure Datadog Docker GCP Kubernetes Network Security Python SIEM Splunk
2 days, 11 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers