SOC Engineer

Security OperationsSecurity OperationsFull TimeRemoteSeniorTeam 1,001-5,000Since 1994H1B No SponsorCompany SiteLinkedIn

Location

Ukraine

Posted

4 days ago

Salary

0

Seniority

Senior

Bachelor Degree3 yrs expUkrainianCloudLinuxSplunk

Job Description

SOC Engineer

Київстар

• Аналізувати, класифікувати та розслідувати сповіщення безпеки, інциденти і підозрілу активність (L2/L3) • Розробляти та оптимізувати правила кореляції, сценарії виявлення загроз, дашборди, алерти та звіти в SIEM • Інтегрувати нові джерела логів у SIEM, налаштовувати парсери та нормалізацію подій • Розвивати use cases і playbooks реагування на інциденти • Взаємодіяти з командами інфраструктури та мереж • Готувати інцидентні звіти, технічні висновки й рекомендації • Брати участь у PoC/Pilot SIEM-рішень, оцінці нових інструментів та розвитку SOC-архітекту

Job Requirements

  • Вища технічна освіта або профільні курси з інформаційної безпеки
  • 3+ років досвіду в кібербезпеці / SOC / Incident Response / Security Operations або суміжних ролях
  • Практичний досвід з SIEM: Microsoft Sentinel, Splunk, QRadar, ArcSight, Wazuh, Elastic, Logsign або аналогами
  • Досвід налаштування кореляційних правил, нотифікацій і дашбордів
  • Розуміння мережевих протоколів, Windows/Linux, Active Directory / Entra ID, cloud та on-prem інфраструктури
  • Знання сучасних методів атак і фреймворку MITRE ATT&CK
  • Вміння якісно документувати розслідування, інциденти та рекомендації

Benefits

  • Офіс або ремоут – вирішувати тобі. Ми даємо можливість працювати будь-де, а робоче місце облаштуємо
  • Ремоут онбординг
  • Перформанс бонуси для всіх (річні чи квартальні — залежить від ролі)
  • Навчаємо працівників: є безліч внутрішніх ресурсів і програм від партнерів, власна бібліотека
  • Страхування здоров’я і життя для працівників
  • Wellbeing-програма та корпоративний психолог
  • Компенсація витрат на мобільний зв'язок Київстар

Related Categories

Related Job Pages

More Security Operations Jobs

Turner & Townsend logo

Project Manager – Security Operations

Turner & Townsend

A global consultancy business serving clients in the real estate, infrastructure and natural resources sectors.

Full TimeRemoteTeam 10,001+H1B No Sponsor

• Act as the Physical Security Point of Contact for EV-charging projects • Establish and maintain detailed project schedules. • Ensure all security deliverables and installations align with the construction or project delivery timeline. • Work closely with Security stakeholders to secure necessary approvals for designs, risk level identification, security guard planning, and hardware deviations. • Manage project delivery across diverse sites within the US and EMEA regions. • Proactively identify potential blockers and escalate issues to leadership with proposed solutions. • Manage stakeholders including architects, engineers, and supply chain to deliver compliant projects. • Production of formal project status reports and other reports as required.

California
$130K - $160K / year
Climb Channel Solutions NA logo

Senior Security Operations Engineer

Climb Channel Solutions NA

A different breed of specialty technology distributor. #ClimbWithUs

Full TimeRemoteTeam 51-200Since 1982H1B No Sponsor

• Lead the development, rollout, and operations of security operations tools and services such as SIEM, EDR, NDR, email, cloud; building detection rules, automated playbooks, and integrations • Serve as a technical resource for security operations analysts; conduct design reviews and provide engineering guidance on detection and response workflows • Apply a detections-as-code approach; version-controlled, peer-reviewed, and tuned against alert quality metrics • Architect and implement security engineering capabilities, including endpoint security, data loss prevention, email security, network security, SIEM enhancements, detection engineering, and security automation. • Partner with cross-functional teams to perform threat modeling and embed security requirements in the development lifecycle. • Research, evaluate, and operationalize security products and services (including AI enabled platforms), building proof-of-concept integrations, provide recommendations or deferrals on adoption, and driving adoption across the security stack.

United States
Unit4 logo

Senior Security Operations Engineer

Unit4

The Next-Generation in Smart Enterprise Resource Planning.

Full TimeRemoteTeam 1,001-5,000Since 1980H1B No Sponsor

Role Description Unit4 Global Cloud Operations Team is seeking a skilled Security Operations Engineer to join our international team. As part of this dynamic team, you will play a key role in maintaining the security and integrity of our cloud infrastructure and environments. You will monitor security systems, analyze threats, and manage security incidents from detection through resolution, ensuring a robust defense against emerging threats. Key Responsibilities - Continuous Monitoring: Continuously monitor cloud environments for potential security threats. - Threat Analysis: Analyze security alerts and logs to identify suspicious activities. - Incident Response: Lead response efforts during security incidents, including containment, eradication, and recovery. - Investigation: Investigate security breaches and identify root causes. - Post-Incident Review: Conduct post-incident analysis to suggest improvements. - Documentation: Document security incidents and maintain detailed records. - Customer Incident Handling: Act on security incidents reported by customers or identified proactively. - Policy Adherence: Follow established security policies and procedures. - System Maintenance: Monitor and maintain security systems such as firewalls, intrusion detection and prevention systems, and SIEM systems. - Preventative Measures: Implement security measures to prevent future incidents. - Staying Current: Stay up-to-date with the latest security trends and technologies. Qualifications - 3+ years of relevant experience in security monitoring, analysis, and incident response. - Knowledge and experience in hardening OS and other environments/systems. - Knowledge and experience with security-related group policies and their implementation. - Knowledge of forensic analysis and incident management tools. - Familiarity with SIEM tools and security incident management. - Strong analytical and problem-solving skills. - Excellent communication skills, both written and verbal. - Ability to work under pressure and manage multiple incidents simultaneously. - Understanding of security policies and procedures. - Experience with firewalls, intrusion detection/prevention systems, and SIEM systems. Requirements - Familiarity with Microsoft Azure & Microsoft certifications. - Experience with AWS. - Experience with scripting languages (e.g. PowerShell) for automation. - Knowledge of networking, and PKI infrastructure. - Basic Linux skills. Benefits - A culture built on trust and accountability - giving you the freedom and autonomy to be successful and make an impact. - Balance - with our Flexible Leave Paid Time Off policy, remote working opportunities, Global Wellbeing Days, and other great benefits. - Growth opportunities - we provide the tools and guidance required so that you can focus on what really matters to you and so, ultimately, you can achieve your best work. - Talented colleagues, role models and mentors - work, learn and be inspired by some of the best talent in the software industry. - A commitment to sustainability - with initiatives such as our Environmental, Social, and Governance strategy and Act4Good programme. - A safe and inclusive working environment – supported by our Employee Resource Groups, which are open to all.

Worldwide
Job Closed
Pan American Health Organization logo

PAHO Consultant - Security Operations and Vulnerability Management Analyst

Pan American Health Organization

PAHO/WHO is committed to providing a respectful and supportive workplace for all personnel. PAHO is an ethical organization that maintains high standards of integrity and accountability. People joining PAHO are required to maintain these standards both in their professional work and personal activities. PAHO also promotes a work environment that is free from harassment, sexual harassment, discrimination, and other types of abusive behavior. PAHO conducts background checks and will not hire anyone who has a substantiated history of abusive conduct. PAHO personnel interact frequently with people in the communities we serve. To protect these people, PAHO has zero tolerance for sexual exploitation and abuse.

ContractRemoteTeam 1,001-5,000

Role Description Information Security Consultant – Security Operations and Vulnerability Management Analyst PAHO is searching for an independent consultant to work at the Department of Information Technology Services (ITS), who will support the operational cybersecurity capabilities of PAHO’s Information Security Program, with focus on security monitoring, incident response, threat hunting, and vulnerability management support. Qualifications - University degree in Information Technology, Information Security, Cybersecurity, Computer Science, Engineering, or other related disciplines from an accredited institution. - Desirable: Specialized training in security operations, incident response, vulnerability management, cloud security, threat hunting, or Microsoft security technologies. - Microsoft Certified: Security Operations Analyst Associate, or equivalent. - GIAC Certified Incident Handler (GCIH) or equivalent. - CompTIA Security+, or equivalent cybersecurity certifications. - ITIL Foundation or equivalent service management certification. - At least seven years of combined relevant professional experience in information security, security operations, incident response, vulnerability management, and/or related areas. - Proven experience performing security monitoring, alert triage, incident analysis, and operational response activities in enterprise environments. - Experience using SIEM, EDR/XDR, vulnerability management, and data security monitoring tools to analyze security events, investigate incidents, and support remediation activities. - Experience supporting vulnerability management processes, including vulnerability analysis, risk-based prioritization, remediation coordination, and validation. - Experience with Microsoft Azure security services and the Microsoft security ecosystem, including Microsoft Sentinel, Defender, Entra ID, Intune, and related security capabilities. - Working knowledge of scripting, query, and automation languages such as PowerShell, Python, KQL, JavaScript, and/or shell scripting. - Ability to work collaboratively with cross-functional teams. - Ability to communicate security incidents, technical findings, vulnerability risks, and remediation recommendations clearly to technical and non-technical stakeholders. - Strong analytical, problem-solving, documentation, coordination, and follow-up skills. - Ability to work under pressure during security incidents and maintain clear documentation of actions taken. - Ability to translate operational security findings into actionable recommendations for detection improvement, incident response, and vulnerability management. - Very good knowledge of English and Spanish. Requirements - Monitor and analyze security alerts and events from Microsoft Sentinel, Microsoft Defender suite, Varonis, and other relevant security tools. - Validate, classify, and prioritize alerts based on severity, affected assets, business impact, exposure, and potential risk to the Organization. - Identify suspicious activity across endpoints, identities, cloud services, data repositories, applications, and infrastructure components. - Provide operational feedback to improve alert quality, reduce false positives, strengthen detection coverage, and optimize monitoring practices. - Support the execution and coordination of incident response activities. - Coordinate incident handling with IT Operations, Service Desk, infrastructure teams, application owners, system custodians, external service providers, vendors, and existing Service Management, Incident Response, and Disaster Recovery processes. - Prepare incident summaries and post-incident notes. - Conduct proactive threat hunting activities across endpoint, identity, cloud, data, and application environments. - Identify indicators of compromise, anomalous behavior, suspicious access patterns, unusual data activity, and potential misuse of organizational resources. - Analyze vulnerability findings from Microsoft Defender, Qualys, and other relevant sources. - Provide security analysis, risk-based prioritization and coordination support for remediation actions. - Prepare periodic summaries of security monitoring activities, notable alerts and incidents, threat hunting findings, vulnerability exposure, and operational risks. - Recommend improvements to detection quality, alert triage, incident handling, vulnerability management workflows, and coordination with external providers. Benefits - Band B - Daily rate $258-$314. - Duration: Until 31 December 2026, possibility of extension subject to performance and availability of funds.

United Kingdom
$258 - $314 / day