Security Operations Specialist
Lead proactive threat detection, incident response, and continuous improvement across our security operations.
The Information Security Department is dedicated to protecting our organization from evolving cyber threats. We are seeking a highly skilled and proactive Security Operations Specialist to join our cybersecurity team. This role offers the opportunity to directly impact our security posture, drive incident response excellence, and shape the continuous improvement of our security operations.
Role
As a Security Operations Specialist, you will:
- Administer and optimize security monitoring and detection tools, refining alert rules and triggers to enhance incident detection and minimize false positives.
- Provide expert guidance and support to the Cyber Incident Response Team (CIRT) for Level 1 incident handling, and lead Level 1 and Level 2 responses when required.
- Maintain and develop cyber response playbooks, standardizing incident handling processes to stay ahead of evolving threats.
- Monitor IT and security infrastructure beyond SOC coverage to ensure comprehensive threat detection.
- Collect, analyze, and report security metrics to maintain IT Security dashboards and KPIs.
- Identify vulnerabilities and misconfigurations in IT security systems, services, and infrastructure, and oversee patch management validation.
- Ensure all systems, equipment, and processes comply with internal IT security policies and standards.
- Collaborate with IT Security colleagues on initiatives and stay current on technological developments and cyber threats.
Profile
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or related field.
- Relevant certifications such as CISSP, CISM, GIAC (GCIH, GCIA), CEH, or equivalent highly preferred.
- Minimum 3 years’ experience in security operations, incident response, or SOC analyst roles.
- Proven expertise in managing and optimizing security monitoring tools (SIEM, IDS/IPS, EDR).
- Experience developing and executing cyber response playbooks and handling Level 1 and Level 2 incidents.
- Solid background in vulnerability management, patch management, and compliance assurance.
- Familiarity with key security domains: Email Security, Identity & Access Management, Network & Application Security, Cloud Security, DDoS & Bot protection, Endpoint Security.
- Knowledge and experience with AWS, Azure, Microsoft 365 Security, Endpoint Detection & Response, Firewall & VPN, Network Anomaly reporting tools, and SIEM technology.
- Experience collaborating with third-party service providers.
Desirable:
- Experience with MDM, WAF, and SQL.
- Excellent analytical skills with the ability to interpret complex security data.
- Strong verbal and written communication skills; experienced in guiding teams and cross-department collaboration.
- Ability to perform under pressure during critical incidents.
- Detail-oriented with a commitment to security compliance and operational excellence.
- Passionate about continuous learning and staying up to date with cybersecurity threats and technologies.
Offer
Be part of a high-impact cybersecurity team safeguarding a dynamic organization.
Work on cutting-edge security technologies and projects.
Continuous learning and professional growth opportunities.
Collaborative and supportive work environment with a focus on innovation and excellence.
3 days remote