Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Talan

Security Operations Analyst – SIEM Operations, Threat Detection

Talan

. Contribute to the development, implementation, validation, tuning and maintenance of security monitoring, analytics and detection capabilities across SIEM, EDR, cloud and other cybersecurity platforms .

Posted 9/25/2026full-timeRemote • PolandMid-LevelSeniorWebsite

Tech Stack

Tools & technologies
AWSAzureCloudCyber SecurityGoogle Cloud PlatformLinuxPythonRubyShell ScriptingSplunk

About the role

Key responsibilities & impact
  • Contribute to the development, implementation, validation, tuning and maintenance of security monitoring, analytics and detection capabilities across SIEM, EDR, cloud and other cybersecurity platforms
  • Support the operation, maintenance, optimization and continuous improvement of security monitoring and threat detection services
  • Participate in onboarding, integration, testing and validation of security data sources, telemetry feeds and monitoring capabilities
  • Contribute to security content management, including use case lifecycle management, rule reviews, testing, tuning and content quality assurance
  • Collaborate with cyber threat intelligence, incident response and cybersecurity operations teams to translate requirements into detection and monitoring capabilities
  • Participate in cybersecurity architecture reviews and provide recommendations to improve security monitoring and detection effectiveness
  • Prepare and maintain cybersecurity operations metrics, dashboards, KPIs and service performance reports
  • Review and assess detections, monitoring configurations, operational processes and service deliverables, identifying improvement opportunities
  • Analyze operational feedback to support tuning, optimization, false-positive reduction and improved detection quality
  • Contribute to quality assurance activities, process reviews, control validation, service quality assessments and corrective actions
  • Support development, review and maintenance of CSOC procedures, standards, documentation, knowledge base articles and operational guidance
  • Prepare and present technical reports, summaries, findings and recommendations to internal and external stakeholders
  • Participate in a rotating on-call schedule to resolve critical system incidents when required

Requirements

What you’ll need
  • +5 years of relevant experience in the information technology field, including triage of alerts and supporting security incidents
  • Proven experience administering a SIEM platform, preferably Splunk or Microsoft Sentinel SIEM
  • Proven experience with SOC tools such as SIEMs and EDRs
  • Ability to autonomously perform technical analysis of security threats and collaborate with the Incident Response team
  • Deep knowledge of Microsoft Security Tools, including M365, Cloud App Security, Azure, Defender for Endpoints, Azure Security, Azure Sentinel and XDR
  • Deep knowledge of cloud technologies, including Azure, AWS and GCP
  • Deep knowledge of SIEM tools such as Splunk, QRadar, ArcSight, Microsoft Sentinel and ELK Stack
  • Knowledge of at least one EDR solution, such as Microsoft Defender for Endpoint or CrowdStrike
  • Knowledge of email security, network monitoring and incident response
  • Knowledge of Linux, Mac and Windows
  • C1 English proficiency
  • Mandatory participation in a rotating 24/7 on-call schedule, approximately one full week every X months
  • Experience building SIEM architectures from initial design to implementation (nice to have)
  • Proven knowledge of monitoring AWS environments (IaaS, SaaS, PaaS) (nice to have)
  • Knowledge of at least one general-purpose or shell scripting language such as Ruby, Bash, PowerShell or Python (nice to have)
  • Desirable certifications: MCSE, CCNA, Microsoft Azure SC-200, GCIH, CEH, GCFA or any GIAC/similar certification
  • Excellent communication skills
  • Customer-facing experience and oral communication skills
  • Ability to write documentation and reports
  • Creativity and ability to find innovative solutions
  • Willingness to learn on the job
  • Conflict management and cooperation

Benefits

Comp & perks
  • Remote position
  • Freelance, full-time contract
  • Training and career development
  • Possibility to be part of a multicultural team
  • Work on international projects