FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Security Operations Analyst – Cyber Defense
Pragmatike. Monitor, triage, and investigate security alerts across SIEM, EDR, Microsoft security tools, and cloud platforms .
Posted 9/25/2026full-timeRemote • India, Sri Lanka, Vietnam, Indonesia, ThailandMid-LevelSeniorWebsite
Tech Stack
Tools & technologiesAWSAzureCloudCyber SecurityFirewallsGoogle Cloud PlatformLinuxMacOSPythonRubySplunk
About the role
Key responsibilities & impact- Monitor, triage, and investigate security alerts across SIEM, EDR, Microsoft security tools, and cloud platforms
- Analyze host and network logs from Windows, Linux, databases, applications, web servers, firewalls, and NIDS/HIDS
- Investigate suspicious activity and identify potential root causes
- Support incident response, remediation, and recovery activities
- Determine appropriate escalation paths and coordinate with relevant cybersecurity teams
- Work with Incident Response specialists to investigate and manage threats
- Identify opportunities to improve detection quality and reduce false positives
- Support security monitoring optimization and whitelist tuning
- Prepare technical reports, summaries, and security findings
- Maintain SOC documentation, procedures, and knowledge-base content
- Contribute to process improvements and operational quality initiatives
Requirements
What you’ll need- 5+ years of relevant IT/cybersecurity experience
- Hands-on experience with security alert triage and incident investigation
- Experience working with SIEM and EDR platforms
- Strong log analysis skills across Windows/Linux and enterprise infrastructure
- Deep knowledge of Microsoft Security technologies
- Experience with Azure, AWS, and/or GCP
- Experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, ArcSight, or ELK
- Experience with at least one EDR solution such as Microsoft Defender for Endpoint or CrowdStrike
- Knowledge of email security, network monitoring, and incident response
- Strong Linux, macOS, and Windows knowledge
- Fluent English with excellent written and verbal communication skills
- Tier-1/Tier-2 Incident Response experience
- AWS security monitoring experience across IaaS, PaaS, or SaaS environments
- Scripting experience with Python, PowerShell, Bash, Ruby, or similar
- Certifications such as SC-200, GCIH, CEH, GCFA, GIAC, CCNA, or MCSE
- Experience working in a global SOC or distributed cybersecurity team
Benefits
Comp & perks- Remote-first work arrangement
- Full-time contract for 6 months, with potential extension
- Hands-on exposure to real-world threat detection and incident response
- Opportunity to work with a global 24/7 Security Operations Centre
- Collaboration with security specialists across different regions and technical disciplines
- Exposure to SIEM, EDR, cloud, network, and endpoint security
- Inclusive and transparent recruitment process