{"id":1139230,"url":"https://alion.io/job/qualysoft-cyber-security-analyst","title":"Cyber Security Analyst","company":{"id":6361,"name":"Qualysoft","domain":"qualysoft.com","url":"https://alion.io/company/qualysoft","size_band":"201-500","is_staffing_agency":false,"is_intermediary":false,"ats_vendor":"Lever","truth_index":{"grade":"B","score":80,"open_postings":30,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":10,"computed_at":"2026-09-23T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"junior","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"hiring_geo_confidence":"structured","locations":["Budapest, Hungary"],"countries":["HU"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":26000,"max_usd":62000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":227},"experience_years_min":2,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Datadog","optional":false},{"name":"Docker","optional":false},{"name":"ElasticSearch","optional":false},{"name":"GCP","optional":false},{"name":"IAM","optional":false},{"name":"Kubernetes","optional":false},{"name":"Linux","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"OpenSearch","optional":false},{"name":"SIEM","optional":false},{"name":"Splunk","optional":false}],"status":"live","first_seen_at":"2026-09-23T09:11:19Z","employer_posted_date":"2026-09-23","last_verified_at":"2026-09-23T22:23:38Z","board_verified":true,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"About the Role\nWe are looking for a Cyber Security Analyst to join our Security Operations team and contribute to the monitoring, investigation, and continuous improvement of our security environment.\nResponsibilities:\nMonitor and respond to security alerts on a 24/7 basis, including participation in an on-call rotation.\nPerform initial alert triage and validation using logs, telemetry, and contextual information (Tier 1 analysis).\nWork directly with internal stakeholders and system owners to validate and investigate security events (Tier 2 analysis).\nEscalate confirmed or high-risk incidents to Tier 3 or Incident Response teams, providing detailed investigation findings.\nDevelop, tune, and continuously improve detection rules, alert logic, and correlation use cases based on real-world threats and the MITRE ATT&CK Framework.\nSupport and co-lead security investigations, including root-cause analysis, identification of lateral movement, and assessment of potential data exposure.\nProactively identify emerging threats through threat hunting and purple teaming exercises.\nContribute to the development and continuous improvement of SOC playbooks, investigation runbooks, and incident response procedures.\nSupport the customization of security response strategies for the specific technical and organizational characteristics of SAP Cloud Infrastructure.\nCreate and maintain security dashboards, metrics, and KPIs to measure SOC effectiveness and monitor threat landscape trends.\nParticipate in lessons-learned reviews and provide recommendations to improve security detection and response processes.\nRequirements:\nBachelor's degree in Computer Science, Information Security, or a related technical field, or equivalent practical experience.\n 2-4 years of experience in a Security Operations Center (SOC) or cybersecurity operations role, preferably in cloud-based or hybrid environments.\nSolid understanding of cloud security principles and experience with Microsoft Azure, AWS, or GCP.\nHands-on experience securing and monitoring workloads in public cloud environments.\nStrong knowledge of security logging, monitoring, and SIEM platforms, such as Splunk, ElasticSearch, OpenSearch, or Datadog.\nExperience with Threat Intelligence Platforms and security monitoring tools.\nStrong understanding of networking protocols, Linux systems, Kubernetes, container technologies, and common security controls.\nFamiliarity with Docker and Kubernetes.\nKnowledge of the MITRE ATT&CK Framework, NIST incident handling lifecycle, and basic malware behavior.\nHands-on experience with security alert triage, basic forensic analysis, and incident response support.\nExperience investigating cloud-native security events, such as IAM misconfigurations, insecure storage, compromised credentials, and unusual container behavior.\nExperience creating and maintaining detection rules and custom alerts.\nExperience using at least one SIEM platform and related log analysis tools.\nFamiliarity with incident handling playbooks, security runbooks, and response procedures.\nBasic understanding of security practices related to Infrastructure as Code (IaC) and static code analysis tools.\nNice to Have:\nExperience working with SAP Cloud Infrastructure or other enterprise cloud environments.\nExperience improving SOC processes, detection capabilities, and incident response workflows.","description_format":"text","description_chars":3365,"description_truncated":false,"requirements":{"experience_years_min":2,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"Hungary","iso":"HU","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Technology","IT Consulting"],"lifecycle":[{"event":"open","at":"2026-09-23T09:51:01Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":0,"expected_fill_days":10,"reasons":["conf:1","win:early","comp:junior"],"computed_at":"2026-09-23T23:41:25Z"},"pay":null,"html_url":"https://alion.io/job/qualysoft-cyber-security-analyst","json_url":"https://alion.io/job/qualysoft-cyber-security-analyst.json","meta":{"generated_at":"2026-09-23T23:41:25Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers"}}