Stop applying to remote jobs that are already dead.
Every listing shows the evidence: when we last checked it, how, and when it was posted and closed.

All listings

Pragmatike via Ashby

Security Operation Analyst (Cyber Defense Operation)

Mexico Level not stated
still open verified 1d ago posted 2d ago seen 2h ago
Apply at jobs.ashbyhq.com

This is the employer's own posting, not a copy on a job board.

What we know

Is it still open?

Confirmed still open

Last checked 1d ago — checked against the employer's own applicant tracking system, which is the company answering directly.

We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.

Check this listing's status as JSON

How old is it?

Posted 2d ago

The date the source published, not the day we noticed it (2026-10-09). Last seen at its source 2h ago.

We have tracked this listing since 9 Oct 2026 (1 days). The employer's own board has carried it every time we have read it, most recently 2 hours ago.

Is it remote?

The listing says yes

The location field doesn't say remote, so our assessment is based on the title or the description. Read the listing before applying.

Who may apply?

Mexico

The description agrees: it names LATAM.

What the ad says
…Location: Remote across LATAM…

Pay not stated

Similar roles pay $1,250–2,300/mo

Middle 50% of 21 listings that do state pay — Operations · all levels · Mexico · USD/month. This employer has published no salary; this is what comparable listings we hold disclose, never converted between currencies or periods. How this is calculated.

Skills named in the ad

AWSAzureBashGCPGDPRIncident ManagementLinuxPythonRubySIEMSplunk

Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.

Carried by 1 source

The listing

Location: Remote across LATAM
Employment: Full-Time Contract
Duration: Long-Term
Language: Fluent English required
Industry: Cybersecurity / Cloud / Enterprise Security

 

About the Opportunity

Pragmatike is recruiting on behalf of a major international organization for a Security Operations Analyst to join a global Cybersecurity Operations team.

You’ll be part of a 24/7 Security Operations Centre (SOC) responsible for monitoring, detecting, investigating, and responding to cyber threats across enterprise, cloud, network, and endpoint environments.

This is a hands-on security role focused on alert triage, threat investigation, log analysis, incident response, and security monitoring, working alongside cybersecurity specialists distributed across multiple regions.

 

What You’ll Do

  • Monitor, triage, and investigate security alerts across SIEM, EDR, Microsoft security tools, and cloud platforms.

  • Analyze host and network logs from Windows, Linux, databases, applications, web servers, firewalls, and NIDS/HIDS.

  • Investigate suspicious activity, identify root causes, and determine appropriate remediation or escalation.

  • Support incident response, remediation, and recovery activities.

  • Work closely with Incident Response and other cybersecurity teams to manage security threats.

  • Analyze network and security events using TCP/IP, syslog, firewall, and network monitoring data.

  • Identify opportunities to improve detection quality and reduce false positives through tuning and optimization.

  • Gather technical information from clients to improve security monitoring and detection.

  • Prepare and present security reports, summaries, and technical findings.

  • Contribute to SOC procedures, documentation, knowledge bases, and quality-control processes.

  • Review operational feedback and implement corrective actions to continuously improve service quality.

 

What We’re Looking For

  • 5+ years of relevant experience in IT/cybersecurity, including security alert triage and incident support.

  • Hands-on experience working in a SOC environment.

  • Strong experience with SIEM and EDR platforms.

  • Advanced log analysis skills across Windows/Linux, databases, applications, and infrastructure.

  • Strong knowledge of Microsoft Security technologies, including Microsoft Sentinel and Defender.

  • Experience with cloud security across Azure, AWS, and/or GCP.

  • Experience with SIEM platforms such as Splunk, QRadar, ArcSight, Microsoft Sentinel, or ELK.

  • Experience with at least one EDR solution such as Microsoft Defender for Endpoint or CrowdStrike.

  • Knowledge of email security, network monitoring, and incident response.

  • Strong knowledge of Linux, macOS, and Windows.

  • Fluent English with excellent written and verbal communication skills.

 

Nice to Have

  • Experience working on an Incident Response team with Tier-1/Tier-2 incident triage.

  • AWS security monitoring experience across IaaS, PaaS, or SaaS environments.

  • Scripting experience with Python, PowerShell, Bash, Ruby, or similar.

  • Certifications such as Microsoft SC-200, GCIH, CEH, GCFA, GIAC, CCNA, or MCSE.

  • Customer-facing cybersecurity experience.

 

Why Join

  • Work inside a global 24/7 cybersecurity operation protecting international organizations.

  • Gain exposure to large-scale cloud, SIEM, EDR, network, and endpoint security environments.

  • Collaborate with cybersecurity specialists across multiple regions and disciplines.

  • Work directly on real-world threat detection and incident response.

  • Build experience across a broad enterprise security technology stack.

 

Pragmatike is committed to a fair, transparent, and inclusive recruitment process. We do not discriminate based on age, disability, gender, gender identity or expression, marital or civil partner status, pregnancy or maternity, race, religion or belief, sex, or sexual orientation.

In accordance with GDPR, your personal data will be processed lawfully, fairly, and securely and used solely for recruitment purposes, including sharing it with our client(s) for employment consideration.

Apply at jobs.ashbyhq.com