Evolution Cloud Services (EVOCS) logo
Evolution Cloud Services (EVOCS)
Posted 20 days agoVerified live 1d ago

Security Analyst

Brief overview

Remote
UndergradOr in progress
$50–$65/hrStated range
2+ yrsMinimum
Security Operations Center (SOC) MonitoringSecurity Alert Triage and ValidationSIEM Query Writing and RefinementIncident ResponseMITRE ATT&CKSecurity Incident ContainmentServiceNowPagerDutyEntra IDTenablePython, PowerShell, KQL, or SPL

About the company

Evolution Cloud Services (EVOCS) logo
Evolution Cloud Services (EVOCS)evocs.tech

EVOCS provides best-in-class digital transformation through our end-to-end services.

Job description

Summary

Evolution Cloud Services (EVOCS) is an IT consulting firm that provides technology solutions and cybersecurity services to help businesses improve performance and achieve their objectives. The Security Analyst monitors and triages client security alerts across a 24x7 SOC, enriches and escalates incidents, performs authorized containment actions, manages cases and handovers, and contributes to threat hunts and detection improvements.

Responsibilities

  • Monitor and triage alerts across a defined client scope, covering the Americas business day within a 24x7 service held across three regions
  • Validate whether an alert represents real activity, and close what does not with a recorded reason
  • Classify severity against a written scale and record the rationale for the classification, not just the outcome
  • Enrich every escalation with asset identity and criticality, the named system owner, exposure context, the identity and its recent behavior, and the blast radius
  • Escalate anything outside the pre-approved action schedule to a named approver, and keep the case moving while you wait
  • Execute containment actions that sit inside the client's pre-approved action schedule — host isolation, session revocation, message purge, block-list changes — and log every one
  • Raise and maintain cases in the client's ITSM platform, and page through the client's on-call tooling; there is no separate EVOCS console holding a second copy of the record
  • Hand over in writing at shift change, and do not stand down until the incoming lead has acknowledged it
  • Feed false positives and noisy rules back to the detection engineer with enough detail to tune against
  • Take part in threat hunts and tabletop exercises as they come round on the rotation

Skills

  • •    2 to 4 years in a SOC, MSSP, incident response team or equivalent monitoring role, with real console time rather than adjacent project work
  • •    Hands-on triage across at least three of: endpoint, identity, network, cloud, email
  • •    Working knowledge of a SIEM and the ability to write and refine your own queries — not only to run somebody else's saved searches
  • •    Practical grasp of how attacks actually proceed: phishing to credential compromise, credential to lateral movement, privilege escalation, persistence, exfiltration
  • •    Familiarity with MITRE ATT&CK as a working tool, not as a certification topic
  • •    Written English clear enough that an escalation needs no translation before a client executive reads it
  • •    Willingness to work a rotating shift pattern across the Americas business day, including weekend rotation
  • •    A disposition to write down what you did, including when it was wrong
  • •    Alert triage and validation
  • •    Escalation enrichment and severity classification
  • •    SIEM query writing and refinement
  • •    Endpoint, identity, network, cloud and email telemetry
  • •    Containment execution within an approved action schedule
  • •    Written handover and case documentation
  • •    Scripting for enrichment or automation — Python, PowerShell, KQL, SPL
  • •    Exposure to SOAR playbook maintenance
  • •    A cloud or security certification: SC-200, Security+, CySA+, GCIA, GCIH, or a vendor SIEM credential
  • •    Any exposure to operational technology, ICS protocols, or IEC 62443 and NIST SP 800-82
  • •    Experience working to a contracted service level rather than best effort

Qualifications

Must Haves

  • •    2 to 4 years in a SOC, MSSP, incident response team or equivalent monitoring role, with real console time rather than adjacent project work
  • •    Hands-on triage across at least three of: endpoint, identity, network, cloud, email
  • •    Working knowledge of a SIEM and the ability to write and refine your own queries — not only to run somebody else's saved searches
  • •    Practical grasp of how attacks actually proceed: phishing to credential compromise, credential to lateral movement, privilege escalation, persistence, exfiltration
  • •    Familiarity with MITRE ATT&CK as a working tool, not as a certification topic
  • •    Written English clear enough that an escalation needs no translation before a client executive reads it
  • •    Willingness to work a rotating shift pattern across the Americas business day, including weekend rotation
  • •    A disposition to write down what you did, including when it was wrong
  • •    Alert triage and validation
  • •    Escalation enrichment and severity classification
  • •    SIEM query writing and refinement
  • •    Endpoint, identity, network, cloud and email telemetry
  • •    Containment execution within an approved action schedule
  • •    Written handover and case documentation

Nice to Haves

  • •    Scripting for enrichment or automation — Python, PowerShell, KQL, SPL
  • •    Exposure to SOAR playbook maintenance
  • •    A cloud or security certification: SC-200, Security+, CySA+, GCIA, GCIH, or a vendor SIEM credential
  • •    Any exposure to operational technology, ICS protocols, or IEC 62443 and NIST SP 800-82
  • •    Experience working to a contracted service level rather than best effort

Benefits

  • Overtime at time and a half beyond 40 hours in a workweek
  • A shift differential for evening and weekend rotation
  • Hybrid work arrangement based on the EVOCS floor
  • Client-provided virtual desktops

More jobs like this