Back to Remote jobs   >   All Others   >   soc analyst
SOC Analyst Consultant @Echelon Risk + Cyber
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 4d ago

[Hiring] SOC Analyst Consultant @Echelon Risk + Cyber

4d ago - Echelon Risk + Cyber is hiring a remote SOC Analyst Consultant. πŸ’Έ Salary: unspecified πŸ“Location: Mexico

Role Description

As SOC Analyst, Consultant, you will act as the lead technical point person for MDR/SOC alerts, working across a portfolio of client environments rather than a single network. You will run deep-dive investigations on endpoint, identity, email, and cloud detections, drive containment and eradication, and tune detection content so that the next alert is better than the last. You will also help mature the service itself - the playbooks, the platform configurations, and the analysts coming up behind you.

What You Will Do:

  • Own Tier 2 and Tier 3 investigations escalated from frontline triage: establish scope and root cause, identify affected hosts, users, and identities, and drive containment, eradication, and recovery.
  • Perform hands-on endpoint investigation and response in EDR/MDR platforms - process and telemetry analysis, remote host triage, artifact collection, host isolation, and analysis of malicious binaries and scripts.
  • Investigate identity and cloud detections across Microsoft 365, Entra ID, Active Directory, AWS, and Azure, including business email compromise, token and session theft, MFA abuse, and privilege escalation.
  • Triage and investigate email security alerts - phishing and BEC analysis, header, URL, and attachment inspection, tenant-wide message trace and remediation, and mail flow and policy recommendations.
  • Review vulnerability scanning and exposure management output, validate findings, and help clients prioritize remediation based on exploitability, exposure, and business context.
  • Write, test, and tune detection content across SIEM and EDR - correlation rules, custom detections, exclusions, and suppression logic - and track the effect on alert quality and false positive rates.
  • Build and maintain automation and SOAR playbooks that take repetitive work out of the triage queue.
  • Run threat hunts using threat intelligence, IoC data, and adversary TTPs mapped to MITRE ATT&CK, and convert hunt findings into durable detections.
  • Document the full incident lifecycle, including root cause analysis and actions taken, and produce clear reports and recommendations for both technical and executive audiences.
  • Serve as the escalation point for confirmed incidents, coordinating with client IT and security teams, Echelon's incident response and offensive security practices, and third parties through to resolution.
  • Support the growth of the Managed SOC/MDR service - standard operating procedures and runbooks, client and platform onboarding, configuration and tuning, quality review of frontline work, and mentoring and training analysts.
  • Participate in after-hours and on-call rotations for SOC alert escalation and response requirements.

Qualifications

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related discipline, or equivalent professional experience.
  • An experienced Tier 2 or Tier 3 SOC analyst, ready to help develop and grow a SOC service and team.
  • Expertise investigating and mitigating security incidents across diverse environments, including on-premises, cloud, and hybrid infrastructures.
  • Hands-on experience investigating across log sources, building and tuning correlation rules and use cases, and writing queries in at least one query language (e.g., CQL, SPL, KQL, YARA-L).
  • Experience investigating phishing, BEC, and malicious delivery, and working with email security platforms (e.g., Microsoft Defender for Office 365, Proofpoint, Mimecast, Abnormal).
  • Ability to interpret scanning and exposure management output (e.g., Tenable, Qualys, Rapid7, Falcon Exposure Management) and prioritize findings using CVSS, EPSS, and known-exploited-vulnerability data.
  • Familiarity with identity platforms (Entra ID, Active Directory), firewall and network telemetry, web and DNS filtering, and endpoint hardening controls.
  • Solid grounding in Windows, Linux, and macOS internals and the forensic artifacts each produces.
  • Ability to read and write scripts (e.g., PowerShell, Python) to parse data, automate triage steps, and build small tools.
  • Strong understanding of threat intelligence integration, adversary TTPs, and the MITRE ATT&CK framework.
  • Clear written and verbal communication - able to walk a system administrator through remediation and brief an executive on impact on the same day.
  • Strong English communication (C1/C2 Level) written and verbal.
  • Authorized to work in Mexico without visa sponsorship.

Requirements

  • 3–5 years of hands-on experience in SOC operations, preferably for a SOC or MDR service provider (e.g., MSSP), supporting multiple clients concurrently.
  • Exposure to additional EDR/XDR platforms (e.g., Microsoft Defender for Endpoint, SentinelOne, Trellix, Blackpoint) and SIEM platforms (e.g., Google SecOps/Chronicle, Splunk, Microsoft Sentinel, IBM QRadar).
  • SOAR and automation experience (e.g., Falcon Fusion, Splunk SOAR, FortiSOAR, Tines, Torq), including API-based integrations between security tools.
  • Digital forensics and malware analysis experience, including memory and disk triage and sandbox analysis.
  • Detection engineering experience against native cloud logging in AWS, Azure, or GCP.
  • Experience supporting purple team exercises, detection validation, or tabletop exercises.
  • Experience mentoring frontline analysts or owning shift and queue quality metrics.

Benefits

  • Access to private medical insurance through MetLife.
  • Life insurance policy via MetLife.
  • 30-day Christmas bonus and a monthly technology stipend.
  • Contribution of 8% of the employee's salary to a savings fund.
  • Flexible vacation policy that allows you to manage your schedule and rest and recharge when you need to.
  • Family-friendly benefits, extended parental leave for when you need to spend critical time with new family members, and employer-paid short-term and long-term disability.
  • Support for individual development through certifications, continued learning, conferences, and more.
Before You Apply
️
remote Be aware of the location restriction for this remote position: Mexico
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Back to Remote jobs   >   All Others   >   soc analyst
SOC Analyst Consultant @Echelon Risk + Cyber
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 4d ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 120,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Mexico
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 120,000+ Remote Jobs
Γ—

Apply to the best remote jobs
before everyone else

Access 120,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews
Unlock All Jobs Now

Maybe later