Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
ES

Lead Cyber Ops Analyst

EPAM Systems
๐Ÿ‡ฆ๐Ÿ‡ท Argentina | ๐Ÿ‡ง๐Ÿ‡ท Brazil | ๐Ÿ‡จ๐Ÿ‡ด Colombia | ๐Ÿ‡ฒ๐Ÿ‡ฝ Mexico
Remote
Staff / Principal
2 days ago
  • triage
  • Incident Response
  • SQL
  • Python
  • AWS
  • Azure
  • GCP
  • CrowdStrike
  • Splunk
  • Wireshark
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV

We are seeking aLead Cyber Ops Analyst to defend complex environments by owning high-severity investigations and elevating detection and hunting capabilities across security domains. You will bridge security operations and detection engineering, automate workflows with scripting and approved AI tools, and mentor others.

Responsibilities

  • Lead complex, multi-signal investigations from triage through root-cause analysis and closure
  • Correlate telemetry across endpoint, identity, network, cloud, and email sources to determine scope and impact
  • Make evidence-based decisions on threat validity, escalation, and containment under ambiguity
  • Conduct threat hunts using intelligence and TTPs to identify gaps in existing detections
  • Build advanced queries to hunt, pivot, and correlate events across disparate data sources
  • Develop scripts to automate enrichment, parsing, correlation, and API integrations
  • Coordinate incident response for significant events, including containment and eradication actions
  • Partner with detection engineering to convert investigative insights into higher-fidelity detections
  • Create and tune detection content and measure detection effectiveness over time
  • Design reusable analytical patterns and automation workflows, including SOAR playbooks
  • Evaluate security tooling by providing structured feedback on coverage, efficacy, and false positives
  • Coach team members and document knowledge into runbooks and hunt guides
  • Apply approved AI tools to accelerate investigations, hunts, and reporting with disciplined verification

Requirements

  • 5+ years of security operations experience in a SOC or cyber analyst role
  • 5+ years of incident response experience owning complex, high-severity investigations end-to-end
  • Proven leadership skills to mentor analysts and codify best practices into runbooks
  • Strong project ownership skills to drive investigations from triage through closure
  • Advanced query skills with KQL or SQL for hunting and event correlation
  • Strong scripting skills in Python for automation, enrichment, and integrations
  • Strong cloud security fundamentals across Amazon Web Services, Microsoft Azure, and Google Cloud Platform
  • Strong security engineering skills to author, tune, and validate detection rules
  • Strong analytical skills to make defensible judgment calls under ambiguity
  • Strong communication skills to coordinate stakeholders during significant incidents
  • Upper-Intermediate English proficiency (B2)
  • Strong collaboration skills to partner with detection engineering and cross-functional teams

Nice to have

  • CrowdStrike Falcon Platform experience
  • Splunk experience
  • Security Orchestration and Automated Response experience
  • Digital forensics experience
  • Wireshark experience

Lead Cyber Ops Analyst ยท EPAM Systems

Auto apply with Likeremote