Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Wursta

Lead Security Operations Analyst

Wursta

. Lead operational triage, analysis, and prioritization of complex security events across multi-tenant client environments .

Posted 9/29/2026full-timeQuito • BrazilSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in incident response, threat hunting, and security event management, with a strong focus on automation and integration of security tools. Proficient in developing and optimizing detection pipelines and ensuring compliance with regulatory standards.

Highest-signal resume keywords
Incident Response ManagementThreat Hunting and Detection EngineeringPython DevelopmentSIEM/XDR Platform ExperienceSecurity Compliance Knowledge

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
PythonNode.jsGoSOAR OrchestrationMachine LearningAI FiltersYARAMITRE ATT&CKNetwork AnalysisAPI Integration
Soft Skills
LeadershipCommunicationAnalytical ThinkingProblem SolvingCollaboration
Tools & Technologies
SplunkMicrosoft SentinelElastic SIEMCrowdStrike FalconAWSAzureGCPDemisto/Cortex XSOARWiresharkGitHub Copilot
Certifications & Qualifications
GCIHGMONGNFACySA+CASP+OSCP
Industry Keywords
NIST SP 800-61r2GDPRLGPDNIST CSF 2.0ISO/IEC 27001:2022Cyber Kill ChainIncident CommanderMulti-Tenant EnvironmentsTelemetry CollectionRegulatory Reporting

Tech Stack

Tools & technologies
AWSAzureBigQueryCloudDNSDockerGoogle Cloud PlatformJavaScriptNode.jsPandasPythonSplunkGo

About the role

Key responsibilities & impact
  • Lead operational triage, analysis, and prioritization of complex security events across multi-tenant client environments
  • Serve as Incident Commander during critical security events, following NIST SP 800-61r2 for containment, eradication, and recovery
  • Lead threat hunting and detection engineering using MITRE ATT&CK, Sigma, and YARA
  • Ensure incident notifications and responses meet contractual SLAs and regulatory reporting timelines
  • Develop production-grade Python, Node.js, or Go code to extend the MSSP application backend
  • Build third-party integrations for EDR, DNS security, threat intelligence, spam/phishing, identity management, firewall, and IDS telemetry
  • Design and build SOAR orchestration playbooks for dynamic triage, identity enrichment, and automated tenant isolation
  • Implement LLM-driven alert summarization and enrichment pipelines using Gemini, BigQuery SIEM data, REST webhooks, RAG pipelines, and MCP servers
  • Optimize detection pipelines with machine learning and AI filters to reduce false positives
  • Align security monitoring with NIST CSF 2.0, ISO/IEC 27001:2022, and NIST SP 800-53r5
  • Ensure incident response and telemetry collection adhere to GDPR, Brazil LGPD, and US state privacy laws

Requirements

What you’ll need
  • Experience in at least one SIEM/XDR platform: Splunk, Microsoft Sentinel, Elastic SIEM, CrowdStrike Falcon, SentinelOne, or Palo Alto Cortex XDR
  • Experience with network and telemetry tools including Wireshark, Zeek, Suricata, PCAP analysis, Syslog, Windows Event Logs, or CloudTrail/CloudWatch
  • Experience with AI and automation tools including Python, Pandas, Requests, REST APIs, Cursor IDE, GitHub Copilot, Claude/OpenAI APIs, LangChain, Webhooks, or Docker
  • Experience with SOAR and scripting tools including Python, PowerShell, Bash, Demisto/Cortex XSOAR, Shuffle, or Tines
  • Knowledge of MITRE ATT&CK, NIST SP 800-61r2, Cyber Kill Chain, YARA, or Sigma Rules
  • Experience with AWS, Azure, or GCP security architectures, IAM, and log architectures
  • 3+ years in a SOC or MSSP environment preferred
  • 2+ years in a Level 3 / Lead SOC capacity preferred
  • Hands-on scripting and API integration experience preferred
  • Proficiency with AI-assisted coding tools preferred
  • Expertise in endpoint, identity, network, and multi-cloud log analysis preferred
  • At least one required certification: GCIH, GMON, GNFA, CySA+, CASP+, or OSCP
  • Fluent English proficiency at a business level; applicants should have a good level of English

Benefits

Comp & perks
  • Autonomy, training, and resources to solve client problems
  • Professional training and development opportunities
  • Hybrid work environment
  • Positive, value-focused work culture
  • Equal employment opportunity