← Back to jobs

Security Operations Analyst (SIEM Operations and Threat Detection)

Talan · Polska, PL · senior

Job Description

We are looking to join a Senior consultant within the Cyber Security Operations Center (CSOC), a globally distributed team of cybersecurity professionals responsible for protecting complex and diverse technology environments.

The role is primarily focused on enhancing threat detection and cybersecurity operations capabilities through activities such as security content management, quality assurance and validation of detection mechanisms, detection use case lifecycle management, onboarding and integration of new security data sources, reporting, and process optimization.

This is an excellent opportunity for professionals interested in working within a large-scale international cybersecurity environment, where they will play a key role in the continuous improvement of security monitoring and threat detection services across multiple customer landscapes. The position combines elements of Security Operations, Threat Detection Engineering, SIEM optimization, cyber risk management, and operational excellence, offering exposure to a wide variety of cybersecurity technologies and challenges.

Main Responsibilities:

  • Contribute to the development, implementation, validation, tuning, and maintenance of security monitoring, analytics, and detection capabilities across SIEM, EDR, cloud, and other cybersecurity platforms.
  • Support the operation, maintenance, optimization, and continuous improvement of security monitoring and threat detection services.
  • Participate in the onboarding, integration, testing, and validation of security data sources, telemetry feeds, and monitoring capabilities.
  • Contribute to security content management activities, including use case lifecycle management, rule reviews, testing, tuning, and content quality assurance.
  • Collaborate with cyber threat intelligence, incident response, and cybersecurity operations teams to translate operational and threat intelligence requirements into effective detection and monitoring capabilities.
  • Under guidance, participate in cybersecurity architecture reviews of new or existing solutions and provide recommendations to enhance security monitoring and detection effectiveness.
  • Contribute to the preparation and maintenance of cybersecurity operations metrics, dashboards, KPIs, and service performance reports.
  • Review, validate, and assess the effectiveness of detections, monitoring configurations, operational processes, and service deliverables, identifying opportunities for improvement.
  • Gather and analyze operational feedback to identify opportunities for tuning, optimization, reduction of false positives, and improvement of overall detection quality.
  • Contribute to quality assurance activities, including process reviews, control validation, service quality assessments, and implementation of corrective actions.
  • Support the development, review, and maintenance of CSOC procedures, standards, documentation, knowledge base articles, and operational guidance materials.
  • Prepare and present technical reports, summaries, findings, and recommendations to internal and external stakeholders.