FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Security Operations Analyst – Cyber Defense Operations
Pragmatike. Monitor, triage, and investigate security alerts across SIEM, EDR, Microsoft security tools, and cloud platforms .
Posted 9/25/2026full-timeRemote • Spain, Greece, Poland, Portugal, Italy, FranceMid-LevelSeniorWebsite
Tech Stack
Tools & technologiesAWSAzureCloudCyber SecurityFirewallsGoogle Cloud PlatformLinuxMacOSPythonRubySplunkTCP/IP
About the role
Key responsibilities & impact- Monitor, triage, and investigate security alerts across SIEM, EDR, Microsoft security tools, and cloud platforms
- Analyze host and network logs from Windows, Linux, databases, applications, web servers, firewalls, and NIDS/HIDS
- Investigate suspicious activity, identify root causes, and determine appropriate remediation or escalation
- Support incident response, remediation, and recovery activities
- Work closely with Incident Response and other cybersecurity teams to manage security threats
- Analyze network and security events using TCP/IP, syslog, firewall, and network monitoring data
- Identify opportunities to improve detection quality and reduce false positives through tuning and optimization
- Gather technical information from clients to improve security monitoring and detection
- Prepare and present security reports, summaries, and technical findings
- Contribute to SOC procedures, documentation, knowledge bases, and quality-control processes
- Review operational feedback and implement corrective actions to continuously improve service quality
Requirements
What you’ll need- 5+ years of relevant experience in IT/cybersecurity, including security alert triage and incident support
- Hands-on experience working in a SOC environment
- Strong experience with SIEM and EDR platforms
- Advanced log analysis skills across Windows/Linux, databases, applications, and infrastructure
- Strong knowledge of Microsoft Security technologies, including Microsoft Sentinel and Defender
- Experience with cloud security across Azure, AWS, and/or GCP
- Experience with SIEM platforms such as Splunk, QRadar, ArcSight, Microsoft Sentinel, or ELK
- Experience with at least one EDR solution such as Microsoft Defender for Endpoint or CrowdStrike
- Knowledge of email security, network monitoring, and incident response
- Strong knowledge of Linux, macOS, and Windows
- Fluent English with excellent written and verbal communication skills
- Experience working on an Incident Response team with Tier-1/Tier-2 incident triage
- AWS security monitoring experience across IaaS, PaaS, or SaaS environments
- Scripting experience with Python, PowerShell, Bash, Ruby, or similar
- Certifications such as Microsoft SC-200, GCIH, CEH, GCFA, GIAC, CCNA, or MCSE
- Customer-facing cybersecurity experience
Benefits
Comp & perks- Work inside a global 24/7 cybersecurity operation protecting international organizations
- Gain exposure to large-scale cloud, SIEM, EDR, network, and endpoint security environments
- Collaborate with cybersecurity specialists across multiple regions and disciplines
- Work directly on real-world threat detection and incident response
- Build experience across a broad enterprise security technology stack
- Potential contract extension after 6 months