Senior Cyber Ops Analyst

EPAM·Argentina, Colombia, Mexico, Brazil·Удалённо·2д. назад

We are looking for a Senior Cyber Ops Analyst to defend complex environments by owning end-to-end investigations, leading threat hunts, and improving detections and response workflows. You will collaborate across security domains and apply automation to raise team effectiveness.

Responsibilities

  • Own complex multi-signal investigations end-to-end from triage to closure
  • Correlate telemetry across endpoint, identity, network, cloud, and email sources to determine scope and impact
  • Decide on escalation and response actions under ambiguity and justify conclusions with evidence
  • Execute threat hunts based on threat intelligence and adversary TTPs to uncover missed activity
  • Write advanced queries to pivot, correlate events, and validate hypotheses across datasets
  • Build automation with scripts and APIs to enrich, parse, and correlate investigative data
  • Lead incident handling for significant events and coordinate containment and eradication actions
  • Partner with detection engineering to translate investigative insights into higher-fidelity detections
  • Author and tune detection content and track effectiveness and false-positive rates
  • Create reusable analytical patterns, runbooks, and hunt guides to improve team execution
  • Mentor analysts and raise the team’s investigation and hunting capability
  • Use approved AI tools to accelerate investigation workflows while verifying outputs
  • Provide structured input for evaluating security tools and coverage gaps

Requirements

  • 3+ years of SOC or security operations experience owning high-severity investigations
  • Incident response leadership experience coordinating containment and eradication across teams
  • Proven project ownership skills driving investigations from triage through root-cause analysis and closure
  • Advanced query skills with KQL and SQL for hunting and event correlation
  • Strong scripting skills in Python or PowerShell for automation and integrations
  • Deep SIEM and EDR experience across common enterprise platforms and telemetry sources
  • Strong detection engineering skills authoring, tuning, and validating detection rules
  • Solid log analysis skills across endpoint, identity, network, email, and cloud data
  • Strong security frameworks knowledge including MITRE ATT&CK and cyber kill chain concepts
  • Strong cloud fundamentals across AWS, Microsoft Azure, and Google Cloud Platform
  • Strong communication skills to document findings and defend conclusions with evidence
  • Upper-Intermediate English proficiency (B2) for clear collaboration and reporting

Nice to have

  • CrowdStrike Falcon Platform experience
  • Splunk experience
  • Security Orchestration and Automated Response experience
  • Digital forensics experience
  • Wireshark packet analysis skills

Похожие вакансии

Другие вакансии EPAM