寻找你的下一个职业机会

按职位、技能和地点搜索招聘信息。准备申请前,先仔细了解职位要求。

找到一个吸引人的职位名称只是求职的起点。请将工作职责、招聘要求和工作条件与你的实际经历进行比较。本指南帮助你筛选机会、准备有针对性的申请材料,并确认每份申请应该在哪里提交。

此界面为简体中文。雇主发布的职位名称和描述保留原文,可能为英文。

清除筛选

搜索结果: 8,529

← 返回搜索结果

Security Operations Analyst (SIEM Operations and Threat Detection)

Talan

地点
Anywhere
发布日期
2026年10月8日

申请前,请在雇主网站确认职位仍在招聘,并检查完整要求和条件。

职位描述

此界面为简体中文。雇主发布的职位名称和描述保留原文,可能为英文。

We are looking to join a Senior consultant within the Cyber Security Operations Center (CSOC), a globally distributed team of cybersecurity professionals responsible for protecting complex and diverse technology environments. The role is primarily focused on enhancing threat detection and cybersecurity operations capabilities through activities such as security content management, quality assurance and validation of detection mechanisms, detection use case lifecycle management, onboarding and integration of new security data sources, reporting, and process optimization. This is an excellent opportunity for professionals interested in working within a large-scale international cybersecurity environment, where they will play a key role in the continuous improvement of security monitoring and threat detection services across multiple customer landscapes. The position combines elements of Security Operations, Threat Detection Engineering, SIEM optimization, cyber risk management, and operational excellence, offering exposure to a wide variety of cybersecurity technologies and challenges. Main Responsibilities: - Contribute to the development, implementation, validation, tuning, and maintenance of security monitoring, analytics, and detection capabilities across SIEM, EDR, cloud, and other cybersecurity platforms. - Support the operation, maintenance, optimization, and continuous improvement of security monitoring and threat detection services. - Participate in the onboarding, integration, testing, and validation of security data sources, telemetry feeds, and monitoring capabilities. - Contribute to security content management activities, including use case lifecycle management, rule reviews, testing, tuning, and content quality assurance. - Collaborate with cyber threat intelligence, incident response, and cybersecurity operations teams to translate operational and threat intelligence requirements into effective detection and monitoring capabilities. - Under guidance, participate in cybersecurity architecture reviews of new or existing solutions and provide recommendations to enhance security monitoring and detection effectiveness. - Contribute to the preparation and maintenance of cybersecurity operations metrics, dashboards, KPIs, and service performance reports. - Review, validate, and assess the effectiveness of detections, monitoring configurations, operational processes, and service deliverables, identifying opportunities for improvement. - Gather and analyze operational feedback to identify opportunities for tuning, optimization, reduction of false positives, and improvement of overall detection quality. - Contribute to quality assurance activities, including process reviews, control validation, service quality assessments, and implementation of corrective actions. - Support the development, review, and maintenance of CSOC procedures, standards, documentation, knowledge base articles, and operational guidance materials. - Prepare and present technical reports, summaries, findings, and recommendations to internal and external stakeholders. On-Call Availability (On-Call Shift System) - Mandatory 24/7 On-Call Rotation: You will be required to participate in a rotating on-call shift schedule from Monday to Sunday. - What this means: This does not mean you will be actively working 24/7 or during late-night shifts. Instead, you will be on standby outside of standard working hours, meaning you must be reachable and available to log in and resolve critical system incidents only if they arise. - Frequency: The approximate rotation frequency is one full week (7 consecutive days) every X months, depending on the number of team members Must have: - +5 years of relevant experience in information technology field, including triage of alerts and supporting security incidents - Proven experience on administering a SIEM platform, preferably either Splunk or MicrosoftSentinel SIEM - Proven experience with the usual toolbox available in a SOC (e.g., SIEMs, EDRs) and being able to autonomously perform technical analysis of security threats and collaborate with Incident Response team - Deep knowledge of Microsoft Security Tools (e.g. M365, Cloud App Security, Azure,Defender for Endpoints, Azure Security, Azure Sentinel and XDR) - Deep Knowledge of Cloud technologies (e.g. Azure, AWS and GCP) - Deep knowledge of SIEM tools like Splunk, QRadar, ArcSight, MS Sentinel, ELK Stac - Knowledge of at least one EDR solution (MS Defender for Endpoint, CrowdStrike) - Knowledge of email security, network monitoring, and incident response - Knowledge of Linux/Mac/Windows - C1 English proficiency Nice to have: - Experience in building SIEM architectures from initial design to implementation, including designing data ingestion pipelines for diverse log sources across cloud and on-prem environments - Proven knowledge of monitoring AWS environment (Iaas, Saas, Paas) - Knowledge of at least one general-purpose or shell scripting language (e.g. Ruby, Bash, PowerShell, Python, etc.) Desirable certifications: - MCSE, CCNA, Microsoft Azure (e.g., SC-200), GCIH, CEH, GCFA or any GIAC/similar certification Required Soft Skills: - Excellent communication skills - Customer-facing experience and oral communication skills - Ability to write documentation & reports - Creativity/ ability to find innovative solutions - Willingness to learn on the job - Conflict management & cooperation What do we offer you? - Remote Position - Freelance, full-time contract. - Training and career development. - Possibility to be part of a multicultural team and work on international projects. If you are passionate about data, development & tech, we want to meet you! Talan Spain’s commitment to non-discrimination based on gender, race, ideology, or any other reason, in accordance with the company’s "Equality Plan" and the current regulations on gender equality between women and men (Royal Decree-Law 6/2019). Talan – Positive Innovation Talan is an international consulting group specializing in innovation and business transformation through technology. With over 7,200 consultants in 21 countries and a turnover of €850M, we are committed to delivering impactful, future-ready solutions. Talan at a Glance Headquartered in Paris and operating globally, Talan combines technology, innovation, and empowerment to deliver measurable results for our clients. Over the past 22 years, we’ve built a strong presence in the IT and consulting landscape, and we’re on track to reach €1 billion in revenue this year. Our Core Areas of Expertise - Data & Technologies: We design and implement large-scale, end-to-end architecture and data solutions, including data integration, data science, visualization, Big Data, AI, and Generative AI. - Cloud & Application Services: We integrate leading platforms such as SAP, Salesforce, Oracle, Microsoft, AWS, and IBM Maximo, helping clients transition to the cloud and improve operational efficiency. - Management & Innovation Consulting: We lead business and digital transformation initiatives through project and change management best practices (PM, PMO, Agile, Scrum, Product Ownership), and support domains such as Supply Chain, Cybersecurity, and ESG/Low-Carbon strategies. We work with major global clients across diverse sectors, including Transport & Logistics, Financial Services, Energy & Utilities, Retail, and Media & Telecommunications.

查找职位、比较要求,再准备申请

从你希望从事的职位或运用的技能开始搜索。调整地点和职业筛选,打开职位比较工作职责。如果没有结果,可以使用更短的关键词,或逐一移除筛选条件。

区分必备要求和优先条件,检查已列出的工作安排、薪资和地点。远程职位也可能要求特定居住国家、工作许可或工作时间重合。请向雇主确认职位信息和完整条件。

选择能够回应职位要求的真实经历,说明你的贡献,只使用能够证实的数字。遵循雇主的申请说明,并在提交前检查联系方式、文档内容和 PDF。

提交申请前的检查清单

求职常见问题

为什么有些职位使用英文?

职位名称和描述由招聘企业撰写。为避免改变招聘要求或工作条件,我们保留原文。操作界面和本指南使用简体中文。如果中文搜索没有结果,可以尝试使用职位发布语言中的名称或技能,例如“software engineer”。搜索词不会自动翻译,界面语言也不代表企业要求的申请语言。

远程职位是否允许从任何国家工作?

不一定。企业可能对居住国家、工作许可或工作时段有要求。请查看原始招聘页面中的具体条件。如果未说明,应先向企业确认,再判断能否从你所在的地区工作。“远程”标签本身并不代表没有地点限制。

搜索没有结果时应该怎么办?

尝试更通用的职位名称或单个技能,并逐一移除筛选条件。不同企业可能用不同名称描述相似工作。如果某个职位已经消失,请在企业招聘页面搜索其职位编号。扩大搜索范围不会让已经关闭的职位重新开放。

申请会通过 ResumizeAI 直接提交吗?

申请按钮会打开外部网站。请按照企业或招聘服务的说明,在该网站完成并确认提交。在 ResumizeAI 中准备简历并不等于已经申请职位。如果链接只打开企业网站,请先找到对应职位,再继续申请流程。

如何针对职位调整简历和求职信?

将招聘要求与能够解释清楚的项目、任务和成果联系起来。突出相关经历,不要添加未经实际掌握的技能或虚构成绩。在求职信中用具体例子说明申请动机,并遵守企业要求的语言和文件格式。提交前检查两份文件,确保内容准确、联系方式正确、链接可用。