Matcha
Workstreet logo

Security Operations Analyst

Workstreet

See similar roles
Apply

AI-powered security firm delivering full-stack security and compliance solutions.

FULL TIMERemote · Asia-Pacific194 employeesPosted Sep 24
security operationsedrsiemfirewall managementipswafincident responsethreat detectionlog analysisalert triagedetection engineeringpythonpowershellsoarsoc 2iso 27001

Remote startup roles in your inbox

Matcha reads all job descriptions to surface the handful that actually matter in a zero noise email. Simple by design.

Describe your next role, cut the noise

Get to know the Security Services Team

We are the team our clients trust to be their eyes and ears around the clock, watching over their environments even when their own teams are offline. Our MDR function spans real-time monitoring and alert triage, threat detection and investigation, and incident analysis and response guidance, using the EDR, SIEM, IPS, WAF, and firewall platforms deployed across our client base to catch what automated rules miss and help clients stop incidents before they become breaches.

We don't just close tickets. Our analysts tune detection logic, document what they see, and escalate with the context client stakeholders need to act fast. If you want to build deep, hands-on detection and investigation experience across a wide range of client environments, and be part of a team that backs each other up on every shift, you'll be in good company here.

The Opportunity

Workstreet is seeking a Security Operations Analyst to join our Security Services team. This is a hands-on monitoring and investigation role: you'll triage and validate alerts, lead deep investigations across EDR, firewall, IPS, WAF, and SIEM tooling, and deliver clear, actionable findings and remediation guidance across our clients' environments, with clients owning execution of the actual response.

You'll work as part of a 24x7 rotating shift schedule, partnering directly with client stakeholders to keep detection coverage strong around the clock. The successful candidate will ramp into our detection stack and client environments quickly, taking ownership of shift-level monitoring, investigation quality, and escalation judgment within their first 30 days.

What you'll do

  • Monitoring & Triage
  • Monitor real-time alerts across EDR, firewall, IPS, WAF, and SIEM platforms, distinguishing true positives from noise under time pressure.
  • Triage and prioritize incoming alerts by severity and business impact across client environments.
  • Maintain continuous coverage during assigned shifts as part of a 24x7 rotation, including nights, weekends, and holidays.

Investigation & Escalation

  • Conduct in-depth investigations into suspicious activity, correlating log and telemetry data across EDR, network, and cloud sources to determine root cause and scope.
  • Deliver clear incident analysis, containment recommendations, and remediation guidance to client teams, who own execution of response actions within their own environments.
  • Analyze firewall, IPS, and WAF logs to identify indicators of compromise, attempted exploitation, and policy violations.
  • Escalate complex or high-severity incidents to client stakeholders with clear, actionable context and next-step recommendations.

Detection Engineering & Documentation

  • Tune and refine SIEM correlation rules and detection logic to reduce false positives and close coverage gaps.
  • Document investigation findings, incident timelines, and remediation recommendations in case management and ticketing systems.
  • Contribute to and maintain SOC runbooks and playbooks for common alert types and incident scenarios.
  • Mentor less experienced analysts on triage methodology and investigative technique.

Client & Cross-Team Collaboration

  • Communicate incident status, findings, and recommended actions clearly to client stakeholders and internal teams.
  • Partner with Workstreet's GRC engineers and vCISOs to ensure detection and response activity supports client compliance obligations (e.g., SOC 2, ISO 27001, HIPAA).
  • Participate in shift handoffs, ensuring continuity of open investigations across the 24x7 rotation.

Who you are

  • 3+ years of hands-on experience monitoring, triaging, and investigating security alerts in a SOC environment.
  • Works daily across EDR, firewall, IPS, WAF, and SIEM platforms and can correlate findings across them.
  • Distinguishes true positives from noise quickly and traces an alert back to root cause under time pressure.
  • Documents findings and explains technical incidents in plain language directly to client stakeholders.
  • Willing and able to work a 24x7 rotating shift schedule, including nights, weekends, and holidays as assigned.
  • Owns complex investigations end-to-end and makes sound triage and escalation calls during active incidents with minimal oversight.
  • Thrives in a fast-paced, collaborative SOC environment and backs up teammates across shift handoffs.


What help you succeed

  • Active security certifications, such as CompTIA Security+, CySA+, GCIH, or equivalent.
  • Experience with EDR platforms (e.g., CrowdStrike, SentinelOne, Microsoft Defender for Endpoint).
  • Experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel, Sumo Logic, Wazuh), including writing or tuning correlation rules.
  • Hands-on administration of security toolsets, including configuring, maintaining, and tuning EDR, SIEM, firewall, IPS, or WAF platforms beyond day-to-day alert triage.
  • Automation experience, including scripting (e.g., Python, PowerShell) or SOAR playbook development to streamline triage, investigation, and reporting workflows.
  • Familiarity with compliance frameworks such as SOC 2, ISO 27001, or HIPAA, and how detection and response activity supports audit readiness.
  • Prior MSSP or managed services experience, supporting multiple client environments concurrently.


What we offer

  • Career Development: Clear path with mentorship and training opportunities.
  • Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
  • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Growth Opportunity: Early-stage company with significant room for career advancement.
  • Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team, within your assigned shift.


What you'll need to thrive

  • Excellent written and verbal English communication skills, with the ability to engage confidently with teammates, clients, and stakeholders across global teams.
  • A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, incident calls, and uninterrupted shift coverage.
  • Commitment to working your assigned shift within Workstreet's 24x7 SOC rotation, including nights, weekends, and holidays as scheduled. Occasional flexibility to adjust shifts is expected to accommodate coverage needs.
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.


Hiring and Selection Process

  • Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
  • Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
  • Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.
  • Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.


Workstreet Is An Equal Opportunity Employer

As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.



More remote jobs at Workstreet

Similar remote jobs