SOC Analyst

Location CO-Bogotá
Posted Date 5 hours ago(8/29/2026 1:58 PM)
Job ID
2026-4825
# Positions
2
Category
ITO

Job Summary

Grant Thornton's Cyber Fusion Centre (CFC) is looking for a technically strong, motivated SOC Analyst to join a follow-the-sun security operations team. This is a hands-on role covering continuous monitoring, alert triage, incident investigation, threat analysis, incident response support, remediation coordination, documentation, and ongoing improvement of detection and response capability.

The CFC operates a tierless SOC model — analysts own the full security operations lifecycle, from initial alert review and triage through investigation, containment support, escalation, documentation, closure, and improvement recommendations.

The primary platform is CrowdStrike Falcon Next-Gen SIEM. Analysts should be comfortable querying and analyzing security data, interpreting detections, correlating events across data sources, assessing suspicious or malicious activity, contributing to investigations, using dashboards and case management tools, and producing clear reporting.

Responsibilities

Security Monitoring & Alert Triage

· Use CrowdStrike Falcon Next-Gen SIEM as the primary platform for real-time monitoring, query-based analysis, detection review, event correlation, case management, and reporting.

· Review, prioritize, and classify alerts using the established severity matrix and SOC operating procedures.

· Determine whether alerts represent false positives, benign activity, suspicious activity, policy violations, or potential security incidents.

· Conduct triage, detailed investigation, evidence review, response coordination, and closure documentation for assigned alerts and incidents.

· Analyze and interpret first-party detections, third-party detections, and correlation rule outputs.

· Maintain accurate triage decisions, evidence notes, and investigation updates in the incident management platform.

 

Incident Response & Remediation

· Ensure incidents are handled promptly in line with SOC runbooks, escalation workflows, and operational expectations.

· Execute approved Cybersecurity Incident Response Plan activities and associated SOC playbooks.

· Support containment, eradication, and recovery activities in coordination with IT resolver teams, platform engineering, IAM, network security, email security, and infrastructure teams.

· Escalate confirmed major incidents to CSIRT or management stakeholders when escalation criteria are met.

· Assist with root cause analysis documentation for major incidents, repeat incidents, or incidents requiring formal review.

 

Threat Analysis & Continuous Improvement

· Support threat hunting, detection validation, and investigation workflows using Falcon Next-Gen SIEM.

· Identify vulnerabilities, suspicious activity, threats, exploits, and weaknesses in security controls.

· Create visualizations, summaries, and investigation reports to communicate event details to SOC leadership and operational stakeholders.

· Recommend improvements to detection logic, correlation rules, dashboards, alert handling procedures, and SOC runbooks.

· Review internal and external threat intelligence advisories, indicators of compromise, and relevant adversary activity.

· Support SOC metrics, quality checks, reporting, and continuous improvement initiatives.

· Support audit, compliance, and evidence requests as required.

 

Shift & Operational Requirements

· Operate within 24x7 security operations and incident response environment.

· Work within a tierless SOC where each analyst may handle triage, investigation, response coordination, documentation, escalation, and closure activities.

· Communicate clearly with technical teams, business stakeholders, management, and, where relevant, legal/privacy and communications teams.

· Follow structured incident response, evidence handling, reporting, and documentation practices.

Skills and Experience

Required Qualifications

· English Level B2+

 

Experience

· 2+ years of experience in security operations, SOC monitoring, SIEM operations, EDR, MDR, incident response, information security, or a related cybersecurity role.

· Experience working in a SOC, MDR, MSSP, enterprise security operations, or similar operational environment.

· Hands-on experience with CrowdStrike Falcon Next-Gen SIEM / EDR strongly preferred.

· Experience with ServiceNow or a similar ITSM/security case management platform.

 

Education

· Bachelor’s degree in computer science, Information Security, Cybersecurity, or a related discipline preferred.

· Equivalent practical experience in cybersecurity operations, incident response, threat hunting, or digital forensics will also be considered.

 

Certifications (Preferred)

· CrowdStrike Certified SIEM Analyst (CCSA)

· CompTIA CySA+

· Other SOC, SIEM, incident response, network security, or digital forensics certifications

 

Core Competencies

· Strong hands-on information security skills

· Strong incident investigation and analytical reasoning skills

· Ownership mindset with strong attention to detail

· Solid understanding of MITRE ATT&CK and the incident response lifecycle

· Excellent written and verbal communication skills

· Ability to brief both technical and non-technical stakeholders

· Strong organization, time management, and attention to detail

· Calm, structured decision-making under high-pressure incidents

· Ability to work independently and as part of a team

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed