775,230open jobs
48,666companies
118,234added this week
Browse all
Salary
≈ $15k – $36k per year (Estimated)
Location
Remote (Philippines)also open in India
Seniority
Middle · 3+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 25, 2026. First seen by Alion on Sep 24, 2026. Workstreet scores B on the Alion truth index.

Overview
Company
Impact
Profile match
SOC 2, CMMC, pentesting & security questionnaires handled by ex-Big Four security leaders and AI that works behind the scenes. You focus on product and customers. We handle the rest.

About Workstreet

At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.

Get to know theSecurity Services Team

We are the team our clients trust to be their eyes and ears around the clock, watching over their environments even when their own teams are offline. Our MDR function spans real-time monitoring and alert triage, threat detection and investigation, and incident analysis and response guidance, using the EDR, SIEM, IPS, WAF, and firewall platforms deployed across our client base to catch what automated rules miss and help clients stop incidents before they become breaches.

We don't just close tickets. Our analysts tune detection logic, document what they see, and escalate with the context client stakeholders need to act fast. If you want to build deep, hands-on detection and investigation experience across a wide range of client environments, and be part of a team that backs each other up on every shift, you'll be in good company here.

The Opportunity

Workstreet is seeking a Security Operations Analyst to join our Security Services team. This is a hands-on monitoring and investigation role: you'll triage and validate alerts, lead deep investigations across EDR, firewall, IPS, WAF, and SIEM tooling, and deliver clear, actionable findings and remediation guidance across our clients' environments, with clients owning execution of the actual response.

You'll work as part of a 24x7 rotating shift schedule, partnering directly with client stakeholders to keep detection coverage strong around the clock. The successful candidate will ramp into our detection stack and client environments quickly, taking ownership of shift-level monitoring, investigation quality, and escalation judgment within their first 30 days.

What you'll do

  • Execute real-time monitoring and triage - monitor alerts across EDR, firewall, IPS, WAF, and SIEM platforms, prioritizing severity and distinguishing true positives under time pressure.
  • Maintain 24x7 shift coverage - deliver continuous threat monitoring as part of a rotating shift schedule including assigned nights, weekends, and holidays.
  • Conduct deep incident investigations - correlate telemetry across EDR, network, and cloud log sources to determine root cause, scope, and indicators of compromise.
  • Deliver remediation guidance - provide clear incident analysis and containment recommendations to client teams who own response execution within their environments.
  • Tune detection logic and rules - refine SIEM correlation rules and detection logic to eliminate false positives and close security coverage gaps.
  • Maintain SOC playbooks and documentation - document investigation findings and incident timelines in case management systems while updating standard operating runbooks.
  • Drive cross-functional security alignment - partner with GRC engineers and vCISOs to ensure threat detection activity supports client compliance obligations.
  • Support shift handoffs and mentorship - execute seamless investigation handoffs across shift rotations while guiding junior analysts on investigative techniques.

Who you are

  • Experienced SOC analyst - bring 3+ years of hands-on experience monitoring, triaging, and investigating security alerts within a high-velocity SOC setting.
  • Multi-platform telemetry investigator - skilled at correlating data daily across EDR, firewall, IPS, WAF, and SIEM tools to trace root causes under pressure.
  • Autonomous incident owner - demonstrated ability to own complex investigations end to end and make sound escalation calls with minimal oversight.
  • Clear technical communicator - able to document findings and explain complex technical incidents in plain language directly to client stakeholders.
  • 24x7 rotation performer - willing and able to work a 24x7 rotating shift schedule, including nights, weekends, and holidays as assigned.
  • Collaborative shift operator - thrives in fast-paced team environments, backing up colleagues across shift transitions and maintaining operational continuity.

What help you succeed

  • Active security credentials - hold recognized industry designations such as CompTIA Security+, CySA+, GCIH, or equivalent credentials.
  • EDR and SIEM platform mastery - practical experience with EDR tools (CrowdStrike, SentinelOne, Defender) and SIEM solutions (Splunk, Microsoft Sentinel, Sumo Logic, Wazuh).
  • Tooling administration and tuning - experience configuring, maintaining, and tuning security platforms beyond day-to-day alert triage.
  • SOAR and automation scripting - proficiency writing Python or PowerShell scripts and developing SOAR playbooks to automate triage workflows.
  • MSSP environment background - prior experience in managed security service provider environments supporting multiple client organizations concurrently.
  • Compliance framework familiarity - awareness of how SOC 2, ISO 27001, and HIPAA requirements align with threat detection and incident response operations.

What we offer

  • Career Development: Clear path with mentorship and training opportunities.
  • Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
  • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Growth Opportunity: Early-stage company with significant room for career advancement.
  • Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team, within your assigned shift.

What you'll need to thrive

  • Excellent written and verbal English communication skills, with the ability to engage confidently with teammates, clients, and stakeholders across global teams.
  • A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, incident calls, and uninterrupted shift coverage.
  • Commitment to working your assigned shift within Workstreet's 24x7 SOC rotation, including nights, weekends, and holidays as scheduled. Occasional flexibility to adjust shifts is expected to accommodate coverage needs.
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.

Hiring and Selection Process

  • Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
  • Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
  • Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.
  • Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.

Workstreet Is An Equal Opportunity Employer

As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
775,230 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
In your city
$125k – $145k per year • Remote (United States) • Full-Time • 4+ years exp • United States
Cybersecurity
SIEM
Apply
≈ $102k – $205k per year (Estimated) • Remote (worldwide) • Full-Time • 7+ years exp • PhD
DevOps
Kali Linux
Azure
Linux
Cybersecurity
Active Directory
Apply
≈ $115k – $211k per year (Estimated) • Remote (United States) • Full-Time • 5+ years exp • Bachelor's Degree • United States
Python
PowerShell
DevOps
Azure
AWS
Cybersecurity
Crowdstrike
Microsoft Sentinel
Microsoft Defender
Least Privilege
Microsoft Defender for Cloud
Microsoft Entra ID
DLP
Management
OneDrive
SharePoint
Apply
$113k – $162k per year • Remote (United States) • Full-Time • 5+ years exp • Bachelor's Degree • Los Angeles
DevOps
Azure
CI/CD
IAM
Cybersecurity
CIS Benchmarks
OWASP
Apply
$105k – $157k per year • Remote (United States) • Full-Time • 3+ years exp • Bachelor's Degree • Los Angeles
Python
PowerShell
DevOps
Splunk
AWS
IAM
Cybersecurity
Crowdstrike
Qualys Cloud Platform
PCI DSS
SOC 2
Carbon Black
SIEM
Apply
≈ $23k – $49k per year (Estimated) • Equity • In office • Full-Time • Bachelor's Degree • Bengaluru
Python
PowerShell
DevOps
Puppet
Ansible
Zabbix
VMWare
Chef
PagerDuty
Prometheus
GitLab CI
CI/CD
Jenkins
Docker
Kubernetes
Grafana
Configuration Management
OpenStack
Incident Management
Linux
Windows
DNS
DHCP
BGP
Cybersecurity
Crowdstrike
Apply
≈ $24k – $59k per year (Estimated) • Equity • Remote (India) • Full-Time • 5+ years exp • India
Python
JavaScript
SQL
Databases
PostgreSQL
AI/ML
AI Agents
LLM
Machine Learning
Frontend
Next.js
React.js
DevOps
gRPC
Ansible
GCP
Helm
VMWare
Azure
CI/CD
ArgoCD
Jenkins
AWS
Kubernetes
Bamboo
AWX
Windows
Cybersecurity
Crowdstrike
Management
Agile
Apply
$165k per year • Equity • In office • Full-Time • Bachelor's Degree • Santa Clara
Python
C#
MATLAB
Apply
≈ $33k – $91k per year (Estimated) • In office • Full-Time
Python
JavaScript
TypeScript
Python
FastAPI
AI/ML
Claude
ChatGPT
Claude Code
LLM
Frontend
Next.js
React.js
DevOps
Terraform
AWS
GitHub
Management
Slack
Apply
≈ $34k – $91k per year (Estimated) • In office • Full-Time
Python
TypeScript
AI/ML
Claude
Claude Code
Langfuse
LLM
OpenAI
LLMOps
DevOps
Terraform
Docker Compose
Kali Linux
AWS CDK
CI/CD
AWS
Docker
Kubernetes
Grafana
GitHub
Amazon S3
Amazon ECS
Linux
Cybersecurity
Metasploit
Nmap
Trivy
Semgrep
Analytics
Metabase
Fivetran
Apply
≈ $25k – $59k per year (Estimated) • Remote (India) • Full-Time • 3+ years exp
Python
PowerShell
DevOps
Splunk
Cybersecurity
Crowdstrike
Wazuh
Microsoft Sentinel
ISO 27001
SentinelOne
SOC 2
GDPR
HIPAA
NIST 800-53
NIST 800-171
FedRAMP
Sumo Logic
SIEM
Apply
≈ $106k – $241k per year (Estimated) • Remote (United States) • Full-Time
Python
AI/ML
LLM
LLM Guardrails
DevOps
Terraform
GCP
CloudFormation
Azure
CI/CD
AWS
Docker
Kubernetes
IAM
Cybersecurity
ISO 27001
SOC 2
GDPR
HIPAA
NIST 800-53
NIST 800-171
FedRAMP
Zero Trust
SIEM
Apply
≈ $13k – $30k per year (Estimated) • Remote (Philippines) • Full-Time
Cybersecurity
ISO 27001
NIST CSF
PCI DSS
SOC 2
GDPR
HIPAA
NIST 800-53
NIST 800-171
FedRAMP
Apply
≈ $122k – $223k per year (Estimated) • Remote (United States) • Full-Time • 8+ years exp
Cybersecurity
ISO 27001
NIST CSF
PCI DSS
SOC 2
GDPR
HIPAA
NIST 800-53
NIST 800-171
FedRAMP
Apply
Remote (India) • Full-Time • Gurgaon
Python
AI/ML
LLM
LLM Guardrails
DevOps
Terraform
GCP
CloudFormation
Azure
CI/CD
AWS
Docker
Kubernetes
IAM
Cybersecurity
ISO 27001
SOC 2
GDPR
HIPAA
NIST 800-53
NIST 800-171
FedRAMP
Zero Trust
SIEM
Apply
See all jobs
This is one of many
775,230 more open roles from verified company boards, updated every day.