# Security Operations Analyst

**Company:** [Huntress](https://hotfix.jobs/companies/huntress)
**Location:** Remote
**Role:** Security Engineering
**Salary:** €70k – €90k/yr
**Experience:** 2+ years
**Skills:** Edr, Mitre Att&Ck, PowerShell, Command Prompt, Wmic, Active Directory, Group Policy, Malware Analysis, Digital Forensics, Incident Response, Microsoft 365, Azure, AWS, GCP, Python
**Posted:** 2026-08-20

> Investigates and responds to security alerts, intrusions, malware, and suspicious cloud activity while providing remediation guidance. The role requires at least two years of SOC or DFIR experience and knowledge of endpoint telemetry, threat actor techniques, administration, networking, and web security.

## Job Description

## Responsibilities
- Triage, investigate, and respond to alerts from the Huntress platform.
- Review EDR telemetry, log sources, and forensic artifacts to determine attack root causes and provide remediation guidance.
- Perform tactical malware analysis while investigating and triaging alerts.
- Investigate suspicious Microsoft 365 activity and provide remediation guidance.
- Assist with threat-related and SOC-relevant escalations from the Product Support team.
- Contribute to detection engineering creation and tuning.
- Contribute to projects that improve outcomes for analysts and partners.
- Collaborate with and mentor teammates.

## Requirements
- 2+ years of experience in a SOC or digital forensics and incident response (DFIR) role.
- Experience with Windows, Linux, and macOS as attack surfaces.
- Experience with threat actor tools and techniques, including the MITRE ATT&CK Framework, PowerShell, Command Prompt, WMIC, scheduled tasks, Service Control Manager, Windows domain and host enumeration, lateral movement, persistence, defense evasion, and other offensive or red-team TTPs.
- Experience with static and dynamic malware analysis concepts.
- Working knowledge of Windows or enterprise domain administration, including Active Directory, Group Policy, and domain trusts.
- Working knowledge of networking concepts, including ports, protocols, NAT, public and private IPs, and VLANs.
- Working knowledge of web technologies, including web servers, web applications, and the OWASP Top 10.
- Effective communication skills and the ability to explain complex events to less technical audiences.
- Strong customer focus, curiosity, and enthusiasm for learning.

## Preferred Qualifications
- Experience in an MSP, MSSP, or MDR role.
- Linux and macOS investigative experience.
- Experience with scripting languages such as PowerShell, Python, Bash, PHP, JavaScript, or Ruby.
- Experience with Hack The Box, TryHackMe, Blue Team Labs Online, or similar platforms.
- Experience conducting cloud-based investigations across Microsoft 365, Azure, AWS, or Google Cloud.
- Participation in cybersecurity competitions such as Capture the Flag events or collegiate cyber defense competitions.
- Familiarity with MSP tools such as remote monitoring and management platforms.

## Compensation and Benefits
- €70,000–€90,000 base salary plus bonus and equity.
- 100% remote work environment.
- New-starter home-office setup reimbursement of £398.
- Generous personal leave entitlements.
- Digital monthly reimbursement of £92.
- Travel to the United States once or twice per year for company events.
- Pension.
- Access to the BetterUp coaching and professional-growth platform.

## Similar jobs

- [Manager, Security Operations](https://hotfix.jobs/jobs/0a4637da-6072-4ec3-a0a9-8b6d4a412d45) - Vanta - Remote - $178k – $209k/yr
- [Intermediate Security Engineer, Security Incident Response Team](https://hotfix.jobs/jobs/049f08fd-cd02-4592-90ca-58c56477f889) - GitLab - Remote
- [Abuse Investigator](https://hotfix.jobs/jobs/067a3725-8094-47e5-a3a6-ac821e7253c6) - Stripe - Dublin, Ireland
- [Abuse Investigator](https://hotfix.jobs/jobs/ba670c7e-d48c-495b-8f3e-648393a93ed7) - Stripe - Seattle, WA
- [Platform Security Engineer](https://hotfix.jobs/jobs/e556dd76-0f95-4dfa-9d3d-e476f24057c0) - Supabase - Remote

**Apply:** https://hotfix.jobs/jobs/8a23a957-23b1-456f-a83e-6105bf82c7af
**Canonical:** https://hotfix.jobs/jobs/8a23a957-23b1-456f-a83e-6105bf82c7af