CybersecurityJobs.io
← Back to all jobs

Job Description

Confiz is hiring a Security Analyst to support its Cybersecurity Operations team in a remote, U.S.-based SOC environment. In this role, you will monitor and triage security alerts during Pacific Time Zone business hours, correlate signals across SIEM, EDR, and firewall data, and document and escalate incidents according to established procedures.

Confiz delivers security operations for a range of organizations, including Fortune 100 retail and CPG companies, leading store chains, fast growth fintech, and multiple Silicon Valley startups. The security team operates within a process-driven framework supported by ISO 9001:2015 (QMS), ISO 27001:2022 (ISMS), ISO 20000-1:2018 (ITSM), and ISO 14001:2015 (EMS).

What you will do

  • Triaging security alerts as the first point of contact, engaging senior analysts and management when required
  • Correlating information from SIEM, EDR, and firewall logs
  • Performing basic log analysis, escalating suspicious activity, and identifying opportunities for improvement
  • Mapping security incidents to MITRE ATT&CK tactics during incident documentation
  • Identifying and escalating data privacy related issues
  • Documenting incidents in ticketing systems
  • Supporting endpoint and network monitoring activities
  • Participating in shift handovers and daily SOC briefings
  • Conducting ongoing security monitoring by understanding basic alert types and triaging low-level events
  • Following established SOC procedures and documenting findings consistently
  • Recognizing when alerts require incident escalation to senior analysts

What you bring

  • 1+ years of experience in IT or security operations (internships or bootcamps acceptable)
  • Basic understanding of networking protocols and operating systems
  • Basic understanding of incident response phases
  • Awareness of common indicators of compromise (IOCs)
  • Familiarity with ticketing systems and escalation procedures
  • Networking basics: TCP/IP, DNS, DHCP, HTTP/S, ICMP
  • Security concepts: CIA triad, types of malware, phishing, brute force, DDoS
  • Operating systems basics: Windows (Event Viewer, Task Manager) and Linux (top, ps, netstat)
  • Security tools exposure, including:
    • SIEM: Splunk (basic search), IBM QRadar (offense monitoring)
    • AV/EDR: Windows Defender, Crowdstrike
    • Ticketing: ServiceNow, Jira
  • Familiarity with SIEM tools and log analysis
  • Basic cloud familiarity: AWS/Azure console navigation and understanding of IaaS, PaaS, SaaS
  • Basic understanding of containerization concepts (Docker, Kubernetes fundamentals)
  • Strong attention to detail and documentation skills
  • Experience using GenAI tools such as ChatGPT (or similar) for threat research assistance and automated report summarization
  • Foundational security certifications (e.g., Security+, Network+, CySA+, GSOC) or actively pursuing certification

Technologies you will work with

  • SIEM, EDR, and firewall tools
  • Splunk, IBM QRadar
  • Windows Defender, Crowdstrike
  • ServiceNow, Jira
  • AWS, Azure
  • Docker, Kubernetes
  • ChatGPT
  • MITRE ATT&CK
  • Windows Event Viewer, Windows Task Manager
  • Linux top, Linux ps, netstat
  • TCP/IP, DNS, DHCP, HTTP/S, ICMP

Schedule and location

  • Remote (remote), U.S. based, working Pacific Time Zone business hours
  • 12-hour shift model (6:30 AM - 6:30 PM Pacific Time)
  • Schedule 1: MON-WED and every 3rd Sunday
  • Schedule 2: WED-FRI and every 3rd Saturday

Similar Jobs