Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
PT

Security Analyst

PRI Technology
๐Ÿ‡บ๐Ÿ‡ธ United States
On-site
2 months ago
  • triage
  • SIEM
  • EDR
  • Python
  • PowerShell
  • Splunk
  • Elastic
  • SQL
  • AI/ML
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV
Security Analyst
Full-time
Onsite - NYC

No 3rd parties please. This role is not eligible for employment-based immigration sponsorship. Applicants must be legally authorized to work in the United States without employer sponsorship, now or in the future.

This role operates within the internal SOC, partnering closely with an external MSSP to maintain 24x7 coverage. The analyst will triage alerts, investigate incidents, and improve detection capabilities through data analysis and automation.

The role emphasizes critical thinking, analytical reasoning, and hands-on scripting to enhance SOC efficiency and detection quality.

Core Responsibilities

SOC Operations & MSSP Oversight

  • Triage and investigate alerts from SIEM, EDR, identity, and cloud platforms
  • Act as the internal escalation point for MSSP-generated alerts
  • Provide direction and feedback to MSSP to improve alert quality and response consistency
  • Validate MSSP findings and ensure appropriate prioritization and remediation

Incident Investigation & Response

  • Conduct structured investigations across endpoint, identity, and network telemetry
  • Correlate data across multiple sources to determine root cause and scope
  • Document incidents with clear timelines, impact assessments, and recommendations

Security Analytics & Detection Engineering

  • Analyze logs and datasets to identify detection gaps and improve signal quality
  • Tune detection logic and reduce false positives
  • Develop and maintain detection use cases aligned to threat frameworks (e.g., MITRE Telecommunication&CK)
  • Design, test, and deploy new detection rules and analytics based on emerging threats and internal findings

Automation & Engineering (Required)

  • Build scripts (Python, PowerShell, or similar) to automate triage, enrichment, and case workflows
  • Integrate tools and APIs to streamline SOC processes
  • Improve case management workflows and response playbooks through automation

Continuous Improvement

  • Propose and implement improvements to monitoring coverage and response processes
  • Contribute to playbooks, runbooks, and detection standards
  • Participate in threat hunting and simulation exercises

Required Skills & Characteristics

Critical Thinking (Primary Evaluation Criteria)

  • Ability to analyze incomplete or ambiguous data and form defensible conclusions
  • Strong hypothesis-driven investigation approach
  • Demonstrated problem-solving in technical or analytical contexts

Technical Skills

  • Hands-on experience with scripting (Python, PowerShell, or similar)
  • Familiarity with SIEM, EDR, and log analysis
  • Understanding of common attack techniques and investigation methods

Analytical Skills

  • Ability to identify patterns and anomalies across datasets
  • Experience working with structured or semi-structured data

Communication

  • Clear, concise incident documentation
  • Ability to challenge and validate MSSP outputs constructively

Nice to Have

  • Experience building detection rules or analytics (Splunk, Sentinel, Elastic, etc.)
  • SQL or data querying experience
  • Exposure to AI/ML-assisted security workflows or automation tools
  • Threat hunting experience

Security Analyst ยท PRI Technology

Auto apply with Likeremote