Vacancy catalog
EPAM
Open role

Security Operations (SOC) Analyst

EPAMMexico
Work model
Remote
Experience
2+ years
Employment
Not specified
Compensation
Not disclosed
Technology signal
9 tags

Technology context

9

Parsed from the vacancy text; ordered by relevance to this role.

AWSAzureSoCLinuxSplunkThreat IntelligenceAutomationSecurity Operation CenterSecurity Operations

Full listing

Role description

We are looking for a Security Operations (SOC) Analyst to strengthen security monitoring, incident response, and detection engineering across a SOC environment. You will triage alerts, hunt threats, improve SOC/SOAR workflows, and communicate findings through clear reporting - apply now to help raise our security posture.

Responsibilities

  • Respond to security incidents and coordinate appropriate containment and remediation actions
  • Triage, investigate, and prioritize security alerts across the SOC toolset
  • Develop and tune rule sets and use cases to improve detection quality and reduce false positives
  • Hunt for threats and support threat intelligence processes, including mapping to TTPs
  • Use advanced analytic tools to identify emerging threat patterns and vulnerabilities
  • Improve SOC/SOAR tooling, workflows, and automation to raise efficiency and coverage
  • Generate clear reports for various stakeholders and communicate findings effectively
  • Plan and run SOC tabletop exercises to validate readiness and response procedures
  • Participate in the on-call rotation every 8th weekend

Requirements

  • 2+ years of experience in Security Operation Center (SOC) operations and security monitoring
  • 2+ years of experience with SIEM and endpoint security tools such as Splunk and Microsoft Defender
  • Strong incident response skills and alert triage capability
  • Solid use case development skills for rule sets and detection logic
  • Good knowledge of malware detection and intrusion detection and prevention systems (IDPS)
  • Strong understanding of Windows, Linux, database, and network device monitoring and logging techniques
  • Good understanding of host and network security hardening, networking protocols, common intrusion techniques, and risk management concepts
  • Strong analytical skills to identify emerging threat patterns and vulnerabilities using advanced analytics
  • High attention to detail and strong logical thinking
  • Curious mindset and confidence to ask questions when needed
  • Upper-Intermediate English proficiency (B2)
  • Availability for on-call duty every 8th weekend

Nice to have

  • Tanium experience or exposure to asset management, patch management, and EDR solutions
  • Qualys experience
  • Azure Sentinel experience
  • AWS security experience
  • ServiceNow SecOps experience