Security Operations Analyst; Cyber Defense Operations
Listed on 2026-09-28
-
IT/Tech
Cybersecurity, Network Security
Trigyn has a contractual opportunity for a Security Operations Analyst (Cyber Defense Operations). This resource will be working remotely.
Required ProfileThe incumbent will be part of the Cybersecurity Operations Section (CSO) to provide front line support to client Partners in the area of information/cyber security, risk management consulting, and security operations activities in collaboration with a team of information and cyber security experts. The resource will be part of the 24x7 Security Operations Centre (CSOC) and will work in close collaboration with team members distributed around the globe to monitor, detect, triage, investigate and respond to cyber threats targeting client or its Clients and Partner Organizations.
Scopeof Work / Duties of Consultant
Reporting to the CSOC Team Lead, the incumbent will conduct the following duties and deliverables:
- Monitor, triage, and investigate alerts across Microsoft security tools, AWS, SIEM platforms, and EDR solutions
- Analyze network and host-based logs (firewalls, NIDS/HIDS, syslog, etc.) to determine appropriate remediation and escalation
- Identify root causes, direct remediation and recovery actions, and support incident response efforts
- Follow structured analytical processes and collaborate with other analysts and teams to ensure effective threat management
- Prepare and present security reports, summaries, and findings to clients
- Contribute to the improvement of CSOC processes and procedures, including quality control procedures, documentation and knowledge base updates
- Gather the necessary information from the client to identify opportunities for whitelist tuning and optimization to reduce false positives and enhance detection quality
- Reviewing feedback and implementing corrective actions to maintain service excellence
- Provide other ad hoc support as required
- A minimum of five (5) years of relevant experience in information technology field, including triage of alerts and supporting security incidents
- Proven experience with the usual toolbox available in a SOC (e.g., SIEMs, EDRs), able to autonomously perform technical analysis of security threats and collaborate with Incident Response team
- Trouble ticket generation and processing experience
- Expert knowledge of Windows, Linux, Database, Application, Web server, etc. log analysis
- Knowledge of Transmission Control Protocol / Internet Protocol (TCP/IP) protocols
- Deep knowledge of Microsoft Security Tools (e.g. M365, Cloud App Security, Azure, Defender for Endpoints, Azure Security, Azure Sentinel and XDR
- Deep knowledge of Cloud technologies (e.g. Azure, AWS and GCP)
- Deep knowledge of SIEM tools like Splunk, QRadar, Arc Sight, MS Sentinel, ELK Stack
- Knowledge of at least one EDR solution (MS Defender for Endpoint, Crowd Strike)
- Knowledge of email security, network monitoring, and incident response
- Knowledge of Linux/Mac/Windows
- Expert knowledge of English, both written and spoken, is required
Experience on an Incident Response team performing Tier I/II initial incident triage.
Proven knowledge of monitoring AWS environment (Iaas, Saas, Paas)
Knowledge of at least one general-purpose or shell scripting language (e.g. Ruby, Bash, Power Shell, Python, etc.)
Required Soft Skills- Excellent communication skills
- Customer-facing experience and oral communication skills
- Ability to write documentation & reports
- Creativity/ ability to find innovative solutions
- Willingness to learn on the job Conflict management & cooperation
- Technical certifications: MCSE, CCNA, Microsoft Azure (e.g., SC-200), GCIH, CEH, GCFA or any GIAC/similar certification
- Relevant industry certifications
TRIGYN TECHNOLOGIES is a multinational IT services company with resources deployed in 28 countries. TRIGYN is an ISO 9001:2015, ISO 27001:2022 (ISMS) and CMMI Level 5 certified company. TRIGYN has offices in the United States, Canada, Switzerland and India.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).