Core Responsibilities

Triage, investigate, and resolve security alerts from EDR, SIEM, cloud security, and identity/SaaS sources. Perform hands-on incident response activities including scoping, containment, evidence collection, and documentation. Build, maintain, and optimize SOAR playbooks and automation workflows to streamline alert handling and response actions.

Requirements

3+ years of experience in security operations or incident response. Hands-on experience with EDR platforms and SIEM for log analysis. Practical experience building or maintaining SOAR playbooks and security automation workflows. Fluent in English with strong communication skills.

Additional Information

Experience Level

Mid-Level

Employment Type

permanent

Work Mode

Remote