We are looking for a Security Operations (SOC) Analyst to strengthen security monitoring, incident response, and detection engineering across a SOC environment. You will triage alerts, hunt threats, improve SOC/SOAR workflows, and communicate findings through clear reporting—apply now to help raise our security posture.
Responsibilities
-
Respond to security incidents and coordinate appropriate containment and remediation actions
-
Triage, investigate, and prioritize security alerts across the SOC toolset
-
Develop and tune rule sets and use cases to improve detection quality and reduce false positives
-
Hunt for threats and support threat intelligence processes, including mapping to TTPs
-
Use advanced analytic tools to identify emerging threat patterns and vulnerabilities
-
Improve SOC/SOAR tooling, workflows, and automation to raise efficiency and coverage
-
Generate clear reports for various stakeholders and communicate findings effectively
-
Plan and run SOC tabletop exercises to validate readiness and response procedures
-
Participate in the on-call rotation every 8th weekend
Requirements
-
2+ years of experience in Security Operation Center (SOC) operations and security monitoring
-
2+ years of experience with SIEM and endpoint security tools such as Splunk and Microsoft Defender
-
Strong incident response skills and alert triage capability
-
Solid use case development skills for rule sets and detection logic
-
Good knowledge of malware detection and intrusion detection and prevention systems (IDPS)
-
Strong understanding of Windows, Linux, database, and network device monitoring and logging techniques
-
Good understanding of host and network security hardening, networking protocols, common intrusion techniques, and risk management concepts
-
Strong analytical skills to identify emerging threat patterns and vulnerabilities using advanced analytics
-
High attention to detail and strong logical thinking
-
Curious mindset and confidence to ask questions when needed
-
Upper-Intermediate English proficiency (B2)
-
Availability for on-call duty every 8th weekend
Nice to have
-
Tanium experience or exposure to asset management, patch management, and EDR solutions
-
Qualys experience
-
Azure Sentinel experience
-
AWS security experience
-
ServiceNow SecOps experience
We offer
-
International projects with top brands
-
Work with global teams of highly skilled, diverse peers
-
Healthcare benefits
-
Employee financial programs
-
Paid time off and sick leave
-
Upskilling, reskilling and certification courses
-
Unlimited access to the LinkedIn Learning library and 22,000+ courses
-
Global career opportunities
-
Volunteer and community involvement opportunities
-
EPAM Employee Groups
-
Award-winning culture recognized by Glassdoor, Newsweek and LinkedIn
EPAM is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, sexual orientation, gender identity or expression, disability, protected veteran status, or any other characteristic protected by applicable law.