Security Analyst
Job title: Security Analyst in USA at Presidio
Company: Presidio
Job description: Description :Presidio, Where Teamwork and Innovation Shape the Future
At Presidio, we’re at the forefront of a global technology revolution, transforming industries through cutting-edge digital solutions and next-generation AI. We empower businesses—and their customers—to achieve more through innovation, automation, and intelligent insights.The Role
Presidio is seeking a detail-oriented and motivated Security Analyst to join our Managed Services team. This is a remote role focused on investigating and triaging security alerts through our SOAR platform in a fast-paced, multi-tenant Managed Detection and Response (MDR) environment.The ideal candidate will demonstrate a strong analytical mindset, foundational threat intelligence knowledge, and the ability to clearly communicate technical findings in client-facing language. Success as a Security Analyst in a fast-paced, multi-tenant MDR environment requires leveraging meticulous attention to detail, advanced pattern recognition, strong threat intelligence acumen, and clear, effective written communication to identify and respond to security threats.Travel Requirements:This is a remote role to reside in the Continental US and does not require any travel.Responsibilities include:
- Security Alert Triage: Investigate and assess security alerts following defined procedures to determine threat severity and scope.
- Incident Response: Conduct initial incident response actions including log collection, asset isolation, and targeted scans; escalate confirmed incidents per protocol.
- Threat Research: Stay up to date on emerging threats, tactics, techniques, and procedures (TTPs) to support investigations.
- Client Communication: Provide timely updates to MDR leadership and convey findings to clients in plain, non-technical language.
- Documentation: Record detailed investigation steps and evidence in case management systems; draft concise, audience-appropriate client summaries.
- Bachelor’s degree or the equivalent work experience and/or military experience
- 1-3 years of hands-on experience with enterprise-level case management tools
- Experience with SIEM platforms such as LogRhythm, Logz.io, or Elasticsearch
- Familiarity with vulnerability scanning tools like Tenable/Nessus
- Regex & Logic Fluency: Working knowledge of regular expressions and Boolean logic, enough to write, read and tweak simple patters and spot anomalies (deep mastery not required)
- Windows Security Knowledge: Familiarity with key Windows security event IDs
- Indicator Pivoting: Ability to interpret security rules and pivot using indicators in SIEM/EDR tools
- Threat Intelligence: Experience with OSINT tools and methods to verify IOCs (e.g., hashes, URLs, IPs)
- Analytical Thinking: Ability to interpret data artifacts, suggest tuning, and make evidence-based decisions
- Technical Foundation: Understanding of Windows logs, networking fundamentals, and common protocols (SMB, RDP, DNS, LDAP, SQL)
- Self-Motivation: Proactive and curious; thrives in a fast-paced, 24/7/365 shift-based environment
- Communication Skills: Strong written and verbal communication with a focus on clarity and professionalism
- Security certifications such as CySA+, GISF (SANS SEC301), SSCP, CEH, or CCNA-Security.
- Experience working in a multi-tenant MSSP/SOC environment.