Jobiglo

No results.

Lead Security Operations Analyst

Wursta

New
Hybrid Senior 🇬🇧 English
Splunk Microsoft Sentinel Elastic SIEM CrowdStrike Falcon SentinelOne Palo Alto Cortex XDR Wireshark Zeek Suricata PCAP analysis Syslog Windows Event Logs Python Pandas Requests Node.js Go PowerShell Bash REST APIs Docker Demisto Cortex XSOAR Shuffle Tines MITRE ATT&CK NIST SP 800-61r2 YARA Sigma AWS Azure Google Cloud Platform IAM Google Gemini Anthropic Claude LangChain Webhooks

Job description

About the role

Wursta is looking for a Lead Security Operations Analyst to head its Managed Security Services Operations (MSSP) team. Based in a hybrid setting in Quito, Ecuador (or El Salvador), the role combines real‑time threat monitoring with AI‑driven automation to protect multi‑tenant cloud environments.

Key responsibilities

  • Lead 24/7 security monitoring, triage, and incident response across client tenants, acting as Incident Commander following NIST SP 800‑61r2.
  • Design and implement AI‑assisted escalation workflows, automated SOAR playbooks, and custom detection rules (Sigma, YARA) using Python, Node.js or Go.
  • Integrate third‑party telemetry (CrowdStrike, SentinelOne, Okta, etc.) and maintain compliance with NIST CSF, ISO 27001, GDPR, LGPD and CCPA.
  • Develop and maintain high‑fidelity detections and threat‑hunting queries based on the MITRE ATT&CK framework.

Required profile

  • 3+ years in a SOC or MSSP environment, with at least 2 years in a Level‑3/lead capacity.
  • Hands‑on experience scripting and building API‑driven automation playbooks.
  • Proven use of AI‑assisted coding tools (e.g., Cursor, GitHub Copilot) for rapid development.
  • Relevant certifications such as GCIH, GMON, GNFA, CySA+, OSCP, or CISSP.

Required skills

  • SIEM/XDR platforms: Splunk, Microsoft Sentinel, Elastic SIEM, CrowdStrike Falcon, SentinelOne, Palo Alto Cortex XDR.
  • Network telemetry tools: Wireshark, Zeek, Suricata, PCAP analysis, Syslog, Windows Event Logs, AWS CloudTrail, CloudWatch.
  • Programming & automation: Python (Pandas, Requests), Node.js, Go, PowerShell, Bash, REST APIs, Docker.
  • SOAR platforms: Demisto, Cortex XSOAR, Shuffle, Tines.
  • Threat frameworks: MITRE ATT&CK, NIST SP 800‑61r2, YARA, Sigma.
  • Cloud environments: AWS, Azure, Google Cloud Platform, IAM, log architectures.
  • AI/LLM tools: Google Gemini, Anthropic Claude, LangChain, Webhooks.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Wursta.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in Ecuador.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 15 hours ago

Expires 1 month from now

6 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Wursta