Security Analyst

Evolution Cloud Services (EVOCS)
$50 - $65Hybrid

About The Position

As a Security Analyst in the EVOCS Security Operations Centre, you watch a client environment that is genuinely monitored rather than nominally monitored, and you decide what is real. Alerts arrive from endpoint, identity, network, cloud, email, and web application telemetry. You validate them, enrich them until they can be acted on, classify the severity, contain what you are authorized to contain, and escalate the rest with the work already done. The measure of this job is not how many alerts you close. It is whether the person who receives your escalation can act on it without going back to the console to ask a question. You cover the Americas business day within a 24x7 service held across three regions, reporting to the SOC Manager through the senior analyst and shift lead on duty.

Requirements

  • 2 to 4 years in a SOC, MSSP, incident response team or equivalent monitoring role, with real console time rather than adjacent project work
  • Hands-on triage across at least three of: endpoint, identity, network, cloud, email
  • Working knowledge of a SIEM and the ability to write and refine your own queries — not only to run somebody else's saved searches
  • Practical grasp of how attacks actually proceed: phishing to credential compromise, credential to lateral movement, privilege escalation, persistence, exfiltration
  • Familiarity with MITRE ATT&CK as a working tool, not as a certification topic
  • Written English clear enough that an escalation needs no translation before a client executive reads it
  • Willingness to work a rotating shift pattern across the Americas business day, including weekend rotation
  • A disposition to write down what you did, including when it was wrong

Nice To Haves

  • Scripting for enrichment or automation — Python, PowerShell, KQL, SPL
  • Exposure to SOAR playbook maintenance
  • A cloud or security certification: SC-200, Security+, CySA+, GCIA, GCIH, or a vendor SIEM credential
  • Any exposure to operational technology, ICS protocols, or IEC 62443 and NIST SP 800-82
  • Experience working to a contracted service level rather than best effort

Responsibilities

  • Monitor and triage alerts across a defined client scope, covering the Americas business day within a 24x7 service held across three regions
  • Validate whether an alert represents real activity, and close what does not with a recorded reason
  • Classify severity against a written scale and record the rationale for the classification, not just the outcome
  • Enrich every escalation with asset identity and criticality, the named system owner, exposure context, the identity and its recent behavior, and the blast radius
  • Escalate anything outside the pre-approved action schedule to a named approver, and keep the case moving while you wait
  • Execute containment actions that sit inside the client's pre-approved action schedule — host isolation, session revocation, message purge, block-list changes — and log every one
  • Raise and maintain cases in the client's ITSM platform, and page through the client's on-call tooling; there is no separate EVOCS console holding a second copy of the record
  • Hand over in writing at shift change, and do not stand down until the incoming lead has acknowledged it
  • Feed false positives and noisy rules back to the detection engineer with enough detail to tune against
  • Take part in threat hunts and tabletop exercises as they come round on the rotation

Benefits

  • Overtime at time and a half beyond 40 hours in a workweek
  • Shift differential for evening and weekend rotation
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service