Senior Security Analyst | Analyste sénior en sécurité
Job Summary
WELCOME TOSITA
At SITA we keep airports moving airlines flying smoothly and borders open. Our technology and communication innovations power the success of the global air travel industry.
Youll find us in 95% of international airports working closely with over 2500 transportation and government clients. Each partnership brings unique challenges and we thrive on delivering fresh solutions and cutting-edge tech to keep operations running like clockwork. We dont just move the world forward were proud to be recognized as aGreat Place to Workby our employees and certified in most of our growing locations.
Here we feel empowered supported and inspired to grow.
Are you ready to love your job The adventure begins right here with you at SITA.
ABOUT THE ROLE & TEAM
Perform investigations and validation of security alerts and incidents to ensure accurate threat identification and response. Continuously improve detection quality and monitoring effectiveness while providing mentorship and guidance to SOC analysts. Drive operational excellence within the SOC by enhancing processes strengthening investigative capabilities and ensuring the timely identification analysis and escalation of security incidents to the Security Incident Response Team (SIRT).
WHAT YOU WILL DO
- Act as the primary escalation point for junior SOC Analysts providing expert guidance and oversight during security investigations.
- Lead complex security incident investigations validating alert classification severity scope and escalation decisions.
- Conduct advanced threat analysis and correlation across SIEM EDR/XDR cloud identity network and endpoint environments.
- Collect analyze and document evidence developing investigation timelines and technical findings to support incident response activities.
- Collaborate with SIRT and cross-functional technical teams ensuring timely escalation of confirmed or suspected security incidents.
- Develop optimize and maintain detection rules correlation logic SOC use cases investigation playbooks and alert tuning activities.
- Identify detection gaps monitoring deficiencies and false-positive trends applying the MITRE ATT&CK framework to strengthen threat detection and monitoring capabilities.
- Mentor SOC Analysts through technical coaching investigation support quality reviews and adherence to SOC standards.
- Provide part-time support to the Vulnerability Management (VM) function including vulnerability validation risk prioritization remediation support and coordination with relevant stakeholders.
- Produce technical reports security assessments operational metrics and stakeholder briefings while supporting tabletop exercises post-incident reviews and continuous improvement initiatives to enhance SOC processes operational efficiency and service quality..
ABOUT YOUR SKILLS
- Advanced experience investigating and responding to security events using SIEM and EDR/XDR platforms.
- Strong understanding of the incident investigation triage and escalation lifecycle within enterprise environments.
- Expertise in analyzing and correlating logs from endpoints cloud services identity platforms networks firewalls proxies VPNs and applications.
- Proven ability to develop tune and optimize detection rules correlation logic and SOC use cases to improve threat detection.
- Proficiency with security query languages such as KQL Lucene EQL and Sigma with scripting experience in PowerShell and/or Python.
- Strong technical knowledge of Windows Linux Active Directory Microsoft 365 Azure/AWS networking and common cyberattack techniques.
- Deep understanding of the MITRE ATT&CK framework and its application to security monitoring threat detection and incident investigations.
- Excellent analytical communication mentoring and documentation skills with a proactive mindset and commitment to continuous learning.
- Bachelors degree in information technology Cybersecurity Computer Science or a related discipline with 35 years of experience in a SOC L2 Analyst or equivalent Security Operations role.
- Industry-recognized cybersecurity certification such as SC-200 GCIH GCIA CySA ECIH or a related credential demonstrating expertise in security operations and incident response.
WHAT WE OFFER
Were all about diversity. We operate in 200 countries and speak 60 different languages and cultures. Were really proud of our inclusive environment. Our offices are comfortable and fun places to work and we make sure you get to work from home too. Find out what its like to join our team and take a step closer to your best life ever.
Flex Week: Work from home up to 2 days/week (depending on your teams needs)
Flex Day: Make your workday suit your life and plans
Flex Location: Take up to 30 days a year to work from any location in the world
Employee Wellbeing: Access our 24/7 EAP and Champion Health platform for all-around wellbeing
Professional Development: Build your skills with LinkedIn Learning and internal training programs
Competitive Benefits: Designed to suit your country and contract type
Equal Employment Opportunity Employer / Veterans / Disabled. SITA is an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard of race color religion sex sexual orientation gender identity national origin or protected veteran status and will not be discriminated against based on disability.
Required Experience:
Senior IC
About Company
At SITA we lead one of the most exciting and advanced industries in the world. With us, there are no limits for people looking to explore the edges of possibility and beyond. We are the world’s leading specialist in air transport communications and information technology. Around the ... View more