_3.22.35 p. m..png?1781029368)
Security Analyst
EVOCS OVERVIEW
EVOCS was founded with a clear purpose: to help businesses operate more effectively, solve complex challenges, and create opportunities for growth through practical expertise and technology solutions.
As an IT consulting firm, we work with our clients to understand their needs, identify the right technologies, and deliver solutions that improve performance and support their business objectives.
Today, EVOCS is a trusted technology partner to a growing number of organizations and industry leaders. Our team combines technical expertise, business understanding, and a commitment to quality to deliver effective solutions and build lasting client relationships based on responsiveness, consistency, and results.
Security Analyst
Cybersecurity / Security Operations | Remote
EVOCS Overview
EVOCS's journey began with a mission to empower businesses with advisory expertise, empowered with ideal technologies to provide them with comprehensive solutions to grow and prosper.
Founded by a team of passionate experts, EVOCS has grown into a trusted partner to a growing number of leaders across their respective industries. Our roots in employee-managed operations reflect our commitment to quality, consistency, and client success.
If you enjoy working in a hyper-fast-growing company, are eager to be part of an agile team, and want to be part of our success story, then let's talk!
🎯 Role Overview
As a Security Analyst in the EVOCS Security Operations Centre, you watch a client environment that is genuinely monitored rather than nominally monitored, and you decide what is real. Alerts arrive from endpoint, identity, network, cloud, email, and web application telemetry. You validate them, enrich them until they can be acted on, classify the severity, contain what you are authorized to contain, and escalate the rest with the work already done.
The measure of this job is not how many alerts you close. It is whether the person who receives your escalation can act on it without going back to the console to ask a question.
You cover the Americas business day within a 24x7 service held across three regions, reporting to the SOC Manager through the senior analyst and shift lead on duty.
🧩 What You Will Do
Monitoring and Triage
• Monitor and triage alerts across a defined client scope, covering the Americas business day within a 24x7 service held across three regions
• Validate whether an alert represents real activity, and close what does not with a recorded reason
• Classify severity against a written scale and record the rationale for the classification, not just the outcome
Enrichment and Escalation
• Enrich every escalation with asset identity and criticality, the named system owner, exposure context, the identity and its recent behavior, and the blast radius
• Escalate anything outside the pre-approved action schedule to a named approver, and keep the case moving while you wait
Containment
• Execute containment actions that sit inside the client's pre-approved action schedule — host isolation, session revocation, message purge, block-list changes — and log every one
Case Management and Handover
• Raise and maintain cases in the client's ITSM platform, and page through the client's on-call tooling; there is no separate EVOCS console holding a second copy of the record
• Hand over in writing at shift change, and do not stand down until the incoming lead has acknowledged it
Improvement and Practice
• Feed false positives and noisy rules back to the detection engineer with enough detail to tune against
• Take part in threat hunts and tabletop exercises as they come round on the rotation
What a Complete Escalation Looks Like
This is the standard the role is measured against, so it is worth stating plainly. An escalation is complete when it carries:
• What happened, in one sentence a non-analyst can follow
• The affected asset, its criticality and its named owner
• The identity involved and what else it did in the detection window
• The blast radius — every other asset, identity or session the confirmed indicator touched
• Exposure context from the vulnerability platform
• The severity, and why that severity and not the one above or below it
• The recommended action, and whether you have already taken it
An escalation missing any of these sends the recipient back to the console. That is the failure mode this role exists to remove.
What You Will Work With
• SIEM and SOAR — the client's platform of record; you work inside their tenancy
• Endpoint — EDR consoles and response APIs
• Identity — Entra ID or equivalent, including sign-in, audit and risk detections
• Network — next-generation firewall logs, DNS filtering, flow data
• Cloud and email — control plane, workload and M365 audit telemetry
• Vulnerability — Tenable or equivalent, for exposure context at triage
• Workflow — ServiceNow for cases, PagerDuty for paging
• Framework — MITRE ATT&CK, and ATT&CK for ICS where operational technology is in scope
Working Pattern and Conditions
• Hybrid role based on the EVOCS floor; client work is done from the floor on client-provided virtual desktops
• Rotating shifts across the Americas business day, with weekend rotation, and no permanent night shift
• The second Americas site covers Phoenix during a declared continuity event, and Phoenix covers it in turn
• Paid at an hourly rate with overtime at time and a half beyond 40 hours in a workweek, plus a shift differential for evening and weekend rotation
• Personal phones and removable media are not permitted at consoles
• Employment is at will
🧠 What You Will Bring
The top candidate will have the following qualifications:
• 2 to 4 years in a SOC, MSSP, incident response team or equivalent monitoring role, with real console time rather than adjacent project work
• Hands-on triage across at least three of: endpoint, identity, network, cloud, email
• Working knowledge of a SIEM and the ability to write and refine your own queries — not only to run somebody else's saved searches
• Practical grasp of how attacks actually proceed: phishing to credential compromise, credential to lateral movement, privilege escalation, persistence, exfiltration
• Familiarity with MITRE ATT&CK as a working tool, not as a certification topic
• Written English clear enough that an escalation needs no translation before a client executive reads it
• Willingness to work a rotating shift pattern across the Americas business day, including weekend rotation
• A disposition to write down what you did, including when it was wrong
Key Skills & Competencies
• Alert triage and validation
• Escalation enrichment and severity classification
• SIEM query writing and refinement
• Endpoint, identity, network, cloud and email telemetry
• Containment execution within an approved action schedule
• Written handover and case documentation
Ideally you have…
• Scripting for enrichment or automation — Python, PowerShell, KQL, SPL
• Exposure to SOAR playbook maintenance
• A cloud or security certification: SC-200, Security+, CySA+, GCIA, GCIH, or a vendor SIEM credential
• Any exposure to operational technology, ICS protocols, or IEC 62443 and NIST SP 800-82
• Experience working to a contracted service level rather than best effort
#LI-Remote
Pay Range for jobs in the US.
Pay Range
$50 - $65 USD
👥 Our Values
We are privileged to serve our loyal customer base in our mission to build lasting relationships with our clients based on trust and mutual success. We strive to deliver exceptional quality and consistency through a white-glove approach. By empowering businesses with tailored solutions and insights, we help them achieve their goals and navigate the ever-evolving tech landscape.
The values we live by:
- Customer-centric Solutions
- Innovation & Excellence
- Integrity & Transparency
- Data-driven Decision Making
📝 Need to Know
The posting will be active for a minimum of 3 days. The active posting will continue to extend by 3 days until the position is filled.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.
Apply for this job
*
indicates a required field
