Remote job
SOC Analyst (Continuity / Coverage)
Job details
About this role
Role overview A Security Operations Center is hiring a continuity analyst whose primary mission is to keep the 24/7 queue fully staffed. The position covers any shift that is short-handed, executing the full Tier 1 alert workflow and stepping into common Tier 2 checks when needed. It is an on-site role based in a delivery centre in Bogotá or Buenos Aires, aligned to U.S. Eastern Time, and dedicated to a single financial-services client.
Responsibilities - Cover day, evening, night, and weekend shifts so the 24/7 roster never runs short, including short-notice cover and planned leave or training gaps. - Execute the complete Tier 1 workload on any shift: alert acknowledgement, validation, enrichment, runbook-driven response, and escalation. - Maintain and improve the shared runbook library, updating outdated steps once for every shift. - Run handover quality checks across crews and shadow new joiners through their first weeks on the queue. - Perform ticket quality reviews and assemble audit evidence for the SOC Manager when staffing allows. - Operate within an access-controlled suite under a clean-desk rule, using VDI-only access to the client environment.
Requirements - Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or a related field, or equivalent hands-on experience. - Prior exposure to security monitoring, or work in a SOC, NOC, or service desk role with security duties. - Solid log fundamentals and triage discipline, including the ability to follow runbooks precisely and recognise when an alert does not fit. - Willingness to rotate across day, evening, night, and weekend shifts as the core of the role. - Clear written documentation skills for runbooks, handovers, and escalations. - Professional working English at B2 or above, sufficient to write and discuss escalations with U.S.-based analysts.
Nice to have - Previous relief, float, or backfill experience in any shift-based operation. - Familiarity with a SIEM such as Elastic, Splunk, Sentinel, or QRadar. - Experience with a security ticketing tool such as ServiceNow. - EDR console work in CrowdStrike Falcon or Microsoft Defender, and identity-alert work in Okta. - Writing procedures or knowledge-base articles, and use of MITRE ATT&CK vocabulary. - Industry certifications such as Security+, CySA+, SC-200, or BTL1.
Benefits and work setup - Full-time on-site position in a delivery centre in Bogotá or Buenos Aires, with senior leads located in the United States. - Progression pathway toward Tier 2, Tier 3, detection engineering, or threat hunting. - No visa sponsorship available; applicants must already be authorised to work in their country of residence.