This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are looking for a Information Security Analyst to serve as a technical leader in designing, implementing, optimizing our tools and processes around Security Operations to safeguard Deel’s information assets and data. You will assist in threat detection and remediation strategy, own and manage the daily alert flow including remediation and lead the incident response when things go wrong. In this role, you will move beyond simple alert triage to focus on deep-dive incident investigation, proactive threat hunting, and the architecture of our detection capabilities. You will actively take part in improving security posture for Deel to defend against internal and external threats.
Job Responsibility:
Own and lead incident response process and actively investigate events generated by security systems, observed and reported suspicious activities with precision and efficiency
Perform digital forensics where applicable
Prioritize alerts based on risk and collaborate with stakeholders for remediation
Administration of SIEM including data ingestion, log management, create and tune alerts to ensure relevancy, accuracy and effectiveness of detection capabilities
Tune detection rules to reduce "noise" and false positives to ensure high-fidelity alerts
Develop and maintain SOPs related to security operations
Build incident response playbooks to standardize workflows and drive effective remediation of security threats
Update detection rules to spot new Indicators of Compromise (IoCs) associated with emerging threat actors
Actively perform threat hunting and help setting guardrails to prevent threats
Design, implement, and maintain comprehensive security dashboards and generate periodic reports to track Security Operations Center (SOC) performance and key risk indicators
Requirements:
5+ years of experience in cybersecurity
Experience with security tools like SIEM, SOAR, EDR, SWG, DLP, CSPM, ZTNA, MDM, IdP, and others
Familiarity with cybersecurity frameworks and best practices, such as MITRE, NIST, CIS, and others
Experience collaborating with internal and external stakeholders for cyber security events/incidents
Have strong interpersonal and communication skills
Stay up to date with the latest security technologies and attack techniques
Experience with conducting security assessments and configuration reviews
Understand and have experience with at least one of the public cloud technologies (Eg AWS, GCP, Azure)
Ability to write query and have scripting or programming experience
Excellent English in both verbal and written
Nice to have:
Certifications like CISSP, GCIH, GCFA, GCIA, CCSP
What we offer:
Stock grant opportunities dependent on your role, employment status and location
Additional perks and benefits based on your employment status and country
The flexibility of remote work, including optional WeWork access