Remote job
Security Operations Analyst
Job details
About this role
Role overview
A security operations role on a privacy-first encrypted vault for personal photos and videos. The analyst will monitor the production environment for anomalies, triage alerts, investigate suspicious activity, and help keep the platform defensible as usage grows.
Responsibilities
- Monitor SIEM alerts, cloud audit logs, and endpoint signals during assigned shifts - Triage and document incidents with timelines, impact assessment, and containment steps - Tune detection rules to reduce noise while preserving coverage for credential abuse and exfiltration attempts - Coordinate with infrastructure teams on patching windows, exposed services, and hardening tasks - Contribute to runbooks for common alert types and after-hours escalation paths
Requirements
- SOC or security operations experience with log analysis and incident triage - Familiarity with cloud provider logging (AWS, GCP, or Azure) and common attack patterns - Calm communication during live incidents and disciplined ticket hygiene - Willingness to participate in an on-call rotation
Benefits and work setup
- Remote-friendly role with global hiring and async-first collaboration across time zones