Source Job

Global

  • Contribute to the development, tuning, and maintenance of security monitoring and detection capabilities across SIEM, EDR, and cloud platforms.
  • Support the onboarding, integration, and testing of security data sources and telemetry feeds.
  • Collaborate with threat intelligence and incident response teams to translate requirements into effective detection mechanisms.

Splunk Microsoft Sentinel EDR SIEM

20 jobs similar to Security Operations Analyst (SIEM Operations and Threat Detection)

Jobs ranked by similarity.

EMEA

  • Monitor, triage, and investigate security alerts across SIEM, EDR, Microsoft security tools, and cloud platforms.
  • Analyze host and network logs from Windows, Linux, databases, applications, web servers, firewalls, and NIDS/HIDS.
  • Support incident response, remediation, and recovery activities while collaborating with global cybersecurity teams.

Pragmatike is a recruitment firm that recruits on behalf of major international organizations in the cybersecurity and cloud security space. They are committed to a fair, transparent, and inclusive recruitment process, fostering a culture of diversity and global collaboration.

Europe

  • Monitor, triage, and investigate security alerts across SIEM, EDR, and cloud environments.
  • Analyze logs from Windows, Linux, databases, and network systems to identify and remediate threats.
  • Work with Incident Response teams to contain threats and improve detection quality.

Talan is a global consulting group specializing in innovation and business transformation through technology. With over 7,200 consultants across 21 countries and an €850M turnover, we deliver future-ready solutions in a multicultural, growth-oriented environment.

India

  • Monitor, triage, and investigate security alerts across SIEM, EDR, Microsoft security tools, and cloud platforms.
  • Analyze host and network logs from Windows, Linux, databases, applications, web servers, firewalls, and NIDS/HIDS.
  • Support incident response, remediation, and recovery activities.

Pragmatike recruits for major international organizations, specializing in cybersecurity and cloud enterprise security. They operate a global 24/7 Cybersecurity Operations Centre with a team of security specialists across different regions.

Colombia

  • Safeguard customer digital assets, sensitive data, and critical systems against cyber threats as part of the MXDR team.
  • Leverage expertise in vulnerability identification, robust security implementation, and incident response to enhance security posture.
  • Collaborate with cross-functional teams to assess risks, formulate security strategies, and ensure adherence to industry standards.

Check Point Software Technologies is a leading vendor of cybersecurity solutions, protecting against sophisticated threats and attacks. The company has been honored by Time Magazine as one of the World’s Best Companies for 2024 and recognized as one of the World’s Top Female-Friendly Places to Work.

$90,000–$100,000/yr
US

  • Monitor, triage, and respond to security alerts and incidents across the security stack.
  • Engineer, implement, and maintain information security technologies such as SIEM, detection rules, and automation.
  • Collaborate with teams to promote information security culture and advise on cyber risk across the organization.

VEIC is a sustainable energy organization working toward a healthy planet, thriving people, and energy justice. The company values an inclusive culture and supports flexible work arrangements, welcoming candidates of all backgrounds.

$85,000–$141,000/yr
US

  • Design, implement, and maintain SIEM platform architectures across AWS, Azure, and GCP environments.
  • Build and operate reliable log collection and ingestion pipelines using forwarders, connectors, APIs, syslog, and agents.
  • Support FedRAMP continuous monitoring and compliance requirements while partnering with detection engineering and security operations teams.

Coalfire is a leading cybersecurity solutions provider that advises, assesses, automates, and helps clients navigate the ever-changing cybersecurity landscape. The company has offices across the U.S. and U.K. and fosters a culture of passionate problem-solvers who are hungry to learn and grow.

$133,000–$209,000/yr
US

  • Design and continuously improve detection and alerting controls to reduce noise and enable rapid response.
  • Build, test, and automate incident response playbooks to increase efficiency across the incident lifecycle.
  • Drive prioritization of alerts using a data-driven triage framework aligned with business impact and threat context.

Sword builds AI to heal billions, pioneering AI Care for healthcare delivery across physical therapy, women’s health, and more. With over 700,000 members and 1,000+ enterprise clients, they have raised $500 million and emphasize a culture of proactive security and AI proficiency.

$157,675–$238,500/yr
US

  • Build, deploy, and continuously improve MITRE ATT&CK–aligned detections across cloud, endpoint, identity, email, and application telemetry with clear false-positive thresholds.
  • Own the full detection lifecycle from hypothesis and data validation through deployment, tuning, and retirement.
  • Advance the detection-as-code platform with version control, peer review, automated testing, CI/CD, and improved pipeline reliability and observability.

Samsara is the pioneer of the Connected Operations™ Cloud, helping organizations that depend on physical operations to harness IoT data for actionable insights. They are a recently public company with a high-caliber team, embracing a flexible working model that supports remote and hybrid work.

US

  • Execute day-to-day implementation, monitoring, and optimization of cybersecurity systems and data pipelines.
  • Support log onboarding, normalization, and validation, as well as detection engineering and SIEM platform operations.
  • Assist in client engagements, security architecture reviews, and automation of response workflows.

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. The company has over 1,300 employees and maintains a culture of collaboration and mentorship.

India

  • Act as a senior member of the SOC, independently managing and resolving security incidents end-to-end.
  • Lead incident investigations, perform root cause analysis, and drive lessons learned.
  • Collaborate with global security teams to develop and improve processes, tooling, and operational best practices.

Netrix Global provides the people, processes, and technology needed to run and scale modern, data-driven businesses that are always on and always secure. The company is consistently ranked in the CRN VAR500 as a top system integrator and fosters a culture of ownership, teamwork, and respect.

Argentina

  • Perform log source onboarding and telemetry analysis to support security assessments.
  • Write and tune detection logic, cut false positives, and build content for coverage gaps.
  • Conduct vulnerability analysis and turn scanner output into prioritized remediation.

EVOCS empowers businesses with advisory expertise and technology solutions to help them grow and prosper. Founded by a team of passionate experts, we have grown into a trusted partner with a commitment to quality, consistency, and client success, operating with an employee-managed culture.

India

  • Monitor security alerts and events to identify potential threats and vulnerabilities.
  • Detect and analyze security incidents using multiple security tools like SIEM, EDR, and IDS/IPS.
  • Respond to security incidents promptly following established procedures and perform phishing analysis.

Zscaler accelerates digital transformation so customers can be more agile, efficient, resilient, and secure with its Zero Trust Exchange platform. The company employs thousands globally and fosters a culture of ownership, collaboration, and continuous feedback.

$172,279–$249,640/yr
United States Canada

  • Build and maintain SIEM infrastructure and detection systems to identify malicious behavior across corporate and production environments.
  • Investigate security incidents end-to-end, including malware analysis and timeline reconstruction, and develop runbooks for scalable response.
  • Partner with IT to enforce security standards on employee devices and drive implementation of Zero-Trust VPN and other corporate security controls.

Quora operates two platforms: Quora, a global knowledge sharing platform, and Poe, a platform for chatting with AI language models. The company fosters a culture of transparency, idea-sharing, and collaboration among its global teams.

US

  • Design, build, and operate high-signal detections across endpoint, identity, cloud, and SaaS environments.
  • Implement and tune detection content across SIEM/XDR/EDR and cloud telemetry using detections-as-code with CI/CD and version control.
  • Proactively hunt for threats, operationalize threat intelligence, and contribute to incident response and automation efforts.

LinkedIn is the world's largest professional network, built to create economic opportunity for every member of the global workforce. They aspire to create a culture built on trust, care, inclusion, and fun where everyone can succeed.

US

  • Support the security team by monitoring and triaging security activity, investigating potential threats, and improving security operations across endpoint, network, and cloud platforms.
  • Assist with developing SIEM detection rules, analyzing security telemetry for anomalous behavior, and conducting targeted threat-hunting activities.
  • Work with vulnerability management, threat intelligence, and documentation to strengthen security practices and ensure adherence to policies.

SimSpace is an AI Proving Ground that helps organizations train, test, and outmaneuver adversaries through realistic cyber simulations. Founded in 2015 by experts from U.S. Cyber Command and MIT Lincoln Laboratory, the company fosters a culture of continuous learning and professional growth, consistently outperforming industry benchmarks in internal mobility and promotions.

US

  • Monitor security tools and analyze logs, alerts, and data for suspicious activity.
  • Investigate potential threats, determine if alerts are real incidents, and identify vulnerabilities.
  • Contain threats, remediate vulnerabilities, document findings, and report to management.

Mercury Insurance helps people reduce risk and overcome unexpected events by providing insurance solutions for over 60 years. They are a midsize employer recognized as one of America's Best Midsize Employers for 2026, fostering a collaborative and inclusive culture.

$150,000–$210,000/yr
US

  • Design, build, and maintain cybersecurity data pipelines using Cribl, managing data flows from source systems into SIEM and data lake platforms.
  • Develop and integrate connectors for security data ingestion, configure parsing, routing, and transformation, and support SIEM architecture and operations.
  • Troubleshoot complex pipeline issues, create documentation, and collaborate with cross-functional teams to ensure data accuracy, security, and performance.

Cribl is a cybersecurity and data engineering company that helps organizations manage and optimize security data pipelines for SIEM and data lake environments. As a growing company with a small team, they emphasize independent problem-solving, collaboration, and a culture that values technical excellence and clear communication.

Australia 12w maternity 12w paternity

  • Triage and investigate intrusions, analyze logs and forensic artifacts to determine root causes.
  • Perform dynamic malware analysis and refine detection capabilities to address emerging threats.
  • Collaborate with product and engineering teams to evolve human-led agentic workflows.

Huntress is a cybersecurity company founded in 2015 by former NSA cyber operators, making enterprise-grade security accessible to businesses of all sizes. They secure over 5 million endpoints and 14 million identities worldwide with a remote-first team and a 24/7 human-led Security Operations Center.

$80,000–$100,000/yr
US

  • Log source onboarding and telemetry analysis for SIEM integration in live client environments.
  • Write and tune detection logic to reduce false positives and address coverage gaps.
  • Turn vulnerability scanner output into prioritized findings using exploitability and asset criticality.

EVOCS is an IT consulting firm helping businesses operate effectively and solve complex challenges through technology solutions. The company serves a loyal customer base with a focus on quality, consistency, and building lasting client relationships based on trust and mutual success.

$140,000–$200,000/yr
United States

  • Lead and grow the SOC, owning detection strategy and incident response across both production and corporate estates.
  • Architect an AI-first operating model for the SOC, building automation for triage, enrichment, and investigation.
  • Partner with Platform Engineering to extend detection into production and cloud workloads, treating detection content as code.

Motive empowers the people who run physical operations with tools to make their work safer, more productive, and more profitable. The company serves nearly 100,000 customers across a wide range of industries, including transportation, logistics, construction, energy, and more.