Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Pragmatike

Security Operations Analyst – Cyber Defense

Pragmatike

. Monitor, triage, and investigate security alerts across SIEM, EDR, Microsoft security tools, and cloud platforms .

Posted 9/25/2026full-timeRemote • India, Sri Lanka, Vietnam, Indonesia, ThailandMid-LevelSeniorWebsite

Tech Stack

Tools & technologies
AWSAzureCloudCyber SecurityFirewallsGoogle Cloud PlatformLinuxMacOSPythonRubySplunk

About the role

Key responsibilities & impact
  • Monitor, triage, and investigate security alerts across SIEM, EDR, Microsoft security tools, and cloud platforms
  • Analyze host and network logs from Windows, Linux, databases, applications, web servers, firewalls, and NIDS/HIDS
  • Investigate suspicious activity and identify potential root causes
  • Support incident response, remediation, and recovery activities
  • Determine appropriate escalation paths and coordinate with relevant cybersecurity teams
  • Work with Incident Response specialists to investigate and manage threats
  • Identify opportunities to improve detection quality and reduce false positives
  • Support security monitoring optimization and whitelist tuning
  • Prepare technical reports, summaries, and security findings
  • Maintain SOC documentation, procedures, and knowledge-base content
  • Contribute to process improvements and operational quality initiatives

Requirements

What you’ll need
  • 5+ years of relevant IT/cybersecurity experience
  • Hands-on experience with security alert triage and incident investigation
  • Experience working with SIEM and EDR platforms
  • Strong log analysis skills across Windows/Linux and enterprise infrastructure
  • Deep knowledge of Microsoft Security technologies
  • Experience with Azure, AWS, and/or GCP
  • Experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, ArcSight, or ELK
  • Experience with at least one EDR solution such as Microsoft Defender for Endpoint or CrowdStrike
  • Knowledge of email security, network monitoring, and incident response
  • Strong Linux, macOS, and Windows knowledge
  • Fluent English with excellent written and verbal communication skills
  • Tier-1/Tier-2 Incident Response experience
  • AWS security monitoring experience across IaaS, PaaS, or SaaS environments
  • Scripting experience with Python, PowerShell, Bash, Ruby, or similar
  • Certifications such as SC-200, GCIH, CEH, GCFA, GIAC, CCNA, or MCSE
  • Experience working in a global SOC or distributed cybersecurity team

Benefits

Comp & perks
  • Remote-first work arrangement
  • Full-time contract for 6 months, with potential extension
  • Hands-on exposure to real-world threat detection and incident response
  • Opportunity to work with a global 24/7 Security Operations Centre
  • Collaboration with security specialists across different regions and technical disciplines
  • Exposure to SIEM, EDR, cloud, network, and endpoint security
  • Inclusive and transparent recruitment process