Security Operations Analyst
LinuxMalware AnalysisMicrosoft 365EDR telemetryPowerShellPythonBashnetworking concepts
About the Role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Operations Analyst based in United States. This role joins a highly specialized Security Operations Center focused on identifying and disrupting cyber threats in real time. You will investigate alerts, analyze endpoint and forensic data, and respond to a wide range of security incidents. The position offers hands-on exposure to active threat actor techniques across Windows, Linux, and macOS environments. You will also contribute to malware analysis, Microsoft 365 investigations, detection engineering, and security improvements. Working alongside experienced security professionals, you will have daily opportunities to strengthen your investigative and analytical capabilities. The environment is collaborative and knowledge-driven, with a strong emphasis on customer protection, continuous learning, and professional growth. This is an opportunity to develop your cybersecurity expertise while directly helping organizations respond to evolving attacks. This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Operations Analyst based in United States. This role joins a highly specialized Security Operations Center focused on identifying and disrupting cyber threats in real time. You will investigate alerts, analyze endpoint and forensic data, and respond to a wide range of security incidents. The position offers hands-on exposure to active threat actor techniques across Windows, Linux, and macOS environments. You will also contribute to malware analysis, Microsoft 365 investigations, detection engineering, and security improvements. Working alongside experienced security professionals, you will have daily opportunities to strengthen your investigative and analytical capabilities. The environment is collaborative and knowledge-driven, with a strong emphasis on customer protection, continuous learning, and professional growth. This is an opportunity to develop your cybersecurity expertise while directly helping organizations respond to evolving attacks. Accountabilities: Triage, investigate, and respond to security alerts generated by the organization's cybersecurity platform. Analyze EDR telemetry, log sources, and forensic artifacts to identify the root cause of attacks and recommend appropriate remediation actions. Perform tactical malware analysis to support the investigation and prioritization of security alerts. Investigate suspicious Microsoft 365 activity and provide recommendations to remediate identified threats. Support escalations from Product Support by addressing threat-related and Security Operations Center questions. Contribute to the creation and tuning of security detections to improve threat identification and response capabilities. Participate in projects designed to improve operational outcomes for analysts and customers. Contribute to a collaborative, peer-mentored environment by sharing knowledge and helping teammates continuously improve. Requirements: Have at least 2 years of experience working in a Security Operations Center or Digital Forensics and Incident Response (DFIR) environment. Demonstrate practical experience investigating Windows, Linux, and macOS environments as attack surfaces. Understand common threat actor tools and techniques, including MITRE ATT&CK, PowerShell, Command Prompt, WMIC, Scheduled Tasks, Service Control Manager, Windows domain and host enumeration, lateral movement, persistence, defense evasion, and other offensive or red-team techniques. Have experience with the fundamental concepts of static and dynamic malware analysis. Have working knowledge of Windows or enterprise domain administration, including Active Directory, Group Policy, and domain trusts. Understand core networking concepts such as common ports and protocols, NAT, public and private IP addresses, and VLANs. Have working knowledge of web technologies and security concepts, including web servers, web applications, and the OWASP Top 10. Communicate effectively and explain complex security incidents to less technical audiences while collaborating across the Security Operations Center and other departments. Demonstrate a strong customer-focused mindset and prioritize customer needs and concerns when making decisions. Bring curiosity, initiative, and genuine enthusiasm for continuously learning about cybersecurity and emerging threats. Previous experience in an MSP, MSSP, or MDR environment is preferred. Experience investigating Linux and macOS environments, cloud platforms such as Microsoft 365, Azure, AWS, or GCP, and managed service provider tools such as RMMs is advantageous. Experience with scripting languages such as PowerShell, Python, Bash, PHP, JavaScript, or Ruby is a plus. Participation in platforms or competitions such as Hack The Box, TryHackMe, Blue Team Labs Online, Capture the Flag events, or collegiate cyber defense competitions is also valued. Benefits: Base compensation ranges from $100,000 to $125,000, plus bonus and equity. The role may also be eligible for on-call or call-in pay in addition to base compensation. The position is fully remote within the United States. The initial training period follows a Monday–Friday schedule, after which schedules may include weekends or a 4x10 shift depending on business requirements. Employees receive generous paid time off, including vacation, sick time, and paid holidays. The benefits package includes comprehensive medical, dental, and vision coverage. Employees receive 12 weeks of paid parental leave. A 401(k) plan includes a 5% company contribution regardless of employee contribution. Life and disability insurance plans are provided. Stock options are available to all full-time employees. Employees receive a one-time $500 reimbursement for building or upgrading a home office. An annual allowance is available for education and professional development. Employees receive a $75 USD monthly digital reimbursement. Access to BetterUp is provided for coaching and personal and professional development. The role offers a collaborative, inclusive environment focused on learning, knowledge sharing, and career growth. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1
You'll be redirected to Jobgether's application page
Job Details
Salary
$100K–$125K
Location
United States
Job type
Full-time
Category
Security Engineering
Experience
2-4 years
Posted
Yesterday
Job Highlights
- $100K–$125K salary
- 2-4 years level role
- 100% Remote — open to candidates in United States
About Jobgether
This job is hosted by Jobgether. Clicking Apply opens their site.
Remote Work Style
Mixed
Mix of flexible and scheduled meetings
Your Match
See how well your skills line up with this role, and what you're missing.
AI Cover Letter
Generate a cover letter tailored to this job from your profile.