Overview
Support Oportun's 24/7 Cyber Security Operations Center by conducting technical analysis of security events and supporting immediate containment, investigation, and remediation. Strengthen defenses by applying knowledge gained throughout the response process.
What you'll do
- Monitor and analyze traffic, security events, and alerts, and advise on appropriate remediation actions.
- Review and assess the impact of security incidents and the remediation actions required to address them.
- Investigate intrusion attempts and analyze exploits by correlating multiple sources to determine affected systems or data sets.
- Follow standard operating procedures for detecting, classifying, documenting, and reporting security incidents.
- Analyze network and host-based security appliance logs, including EDR, firewalls, NIDS, HIDS, and system logs, to determine remediation actions and escalation paths.
- Independently identify, contain, analyze, document, and eradicate malicious activity in accordance with established procedures.
- Escalate intrusion events, security incidents, threat indicators, and warning information to the appropriate client and stakeholders.
- Look for practical ways to use AI tools thoughtfully to work smarter, reduce manual work, and make better decisions faster.
What you'll need
- A bachelor's degree in computer science, information systems, or a related field from an accredited institution, or 2–5 years of relevant experience in SOC, incident response, or cyber forensics.
- At least 2 years of prior SOC experience, including relevant internships.
- Experience working with Splunk SIEM and analyzing logs from security devices such as firewalls, proxies, and EDR platforms.
- Hands-on experience handling cyber incidents, performing L1 ticket analysis, identifying false positives, and correlating incidents.
- Understanding of network architecture and the ability to connect events logically across systems and environments.
- Working knowledge of the TCP/IP suite and OSI protocol layers, network and systems architecture, and intrusion detection systems.
- Understanding of web application architecture, Active Directory, and major application-layer protocols such as HTTP, SMTP, and DNS.
- Understanding of common malware categories and how they function, including rootkits, trojans, adware, exploits, and fileless malware.
- Strong organizational, time-management, prioritization, documentation, and communication skills, with the ability to work effectively across functional and organizational boundaries.
- Comfort working in a fast-paced environment, prioritizing competing demands, and meeting deadlines.
- Effective communication across functional boundaries and the ability to build strong partnerships with engineering and security teams.
- Genuine interest in security, technology, and automation.
- Comfort navigating complexity and moving forward without perfect information.
- Ability to communicate clearly, give direct feedback, and expect the same in return.
Nice to have
- Experience working with or partnering closely with network, engineering, and application teams.
- A preferred security certification such as Security+ or a similar credential.
- Experience using AI tools (ChatGPT, Copilot, or similar) to improve personal productivity.
Details
- Remote position that must be performed from within India.
- The role supports a 24/7 Cyber Security Operations Center.
Read the full description and apply on the company’s own careers page.