Security Operations Analyst
Investigates and responds to security alerts, intrusions, malware, and suspicious cloud activity while providing remediation guidance. The role requires at least two years of SOC or DFIR experience and knowledge of endpoint telemetry, threat actor techniques, administration, networking, and web security.
About the job
Responsibilities
- Triage, investigate, and respond to alerts from the Huntress platform.
- Review EDR telemetry, log sources, and forensic artifacts to determine attack root causes and provide remediation guidance.
- Perform tactical malware analysis while investigating and triaging alerts.
- Investigate suspicious Microsoft 365 activity and provide remediation guidance.
- Assist with threat-related and SOC-relevant escalations from the Product Support team.
- Contribute to detection engineering creation and tuning.
- Contribute to projects that improve outcomes for analysts and partners.
- Collaborate with and mentor teammates.
Requirements
- 2+ years of experience in a SOC or digital forensics and incident response (DFIR) role.
- Experience with Windows, Linux, and macOS as attack surfaces.
- Experience with threat actor tools and techniques, including the MITRE ATT&CK Framework, PowerShell, Command Prompt, WMIC, scheduled tasks, Service Control Manager, Windows domain and host enumeration, lateral movement, persistence, defense evasion, and other offensive or red-team TTPs.
- Experience with static and dynamic malware analysis concepts.
- Working knowledge of Windows or enterprise domain administration, including Active Directory, Group Policy, and domain trusts.
- Working knowledge of networking concepts, including ports, protocols, NAT, public and private IPs, and VLANs.
- Working knowledge of web technologies, including web servers, web applications, and the OWASP Top 10.
- Effective communication skills and the ability to explain complex events to less technical audiences.
- Strong customer focus, curiosity, and enthusiasm for learning.
Preferred Qualifications
- Experience in an MSP, MSSP, or MDR role.
- Linux and macOS investigative experience.
- Experience with scripting languages such as PowerShell, Python, Bash, PHP, JavaScript, or Ruby.
- Experience with Hack The Box, TryHackMe, Blue Team Labs Online, or similar platforms.
- Experience conducting cloud-based investigations across Microsoft 365, Azure, AWS, or Google Cloud.
- Participation in cybersecurity competitions such as Capture the Flag events or collegiate cyber defense competitions.
- Familiarity with MSP tools such as remote monitoring and management platforms.
Compensation and Benefits
- €70,000–€90,000 base salary plus bonus and equity.
- 100% remote work environment.
- New-starter home-office setup reimbursement of £398.
- Generous personal leave entitlements.
- Digital monthly reimbursement of £92.
- Travel to the United States once or twice per year for company events.
- Pension.
- Access to the BetterUp coaching and professional-growth platform.
Skills
Edr, Mitre Att&Ck, PowerShell, Command Prompt, Wmic, Active Directory, Group Policy, Malware Analysis, Digital Forensics, Incident Response, Microsoft 365, Azure, AWS, GCP, Python
Similar jobs
Security Engineering jobsLeads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.
This remote Security Incident Response Engineer detects, investigates, and resolves security incidents while improving automation, documentation, and detection capabilities. The role requires SIEM and cloud experience, Python skills or willingness to learn, and an interest in forensic investigations.
Investigates high-risk accounts and leads incident response for fraud and product-abuse events, using behavioral analysis and threat intelligence to identify root causes and improve detection. Requires 3+ years of incident response and fraud-data analysis experience, plus strong Python and SQL skills.
Investigates and leads response to high-risk fraud and product-abuse incidents, analyzes threat patterns, and drives root-cause and prevention improvements. Requires 3+ years of incident response and fraud-oriented data analysis, plus Python, SQL, and security investigation expertise.
Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.