At SITA, we keep airports moving, airlines flying smoothly, and borders open. Our technology and communication innovations power the success of the global air travel industry. You ll find us in 95% of international airports, working closely with over 2,500 transportation and government clients. Each partnership brings unique challenges, and we thrive on delivering fresh solutions and cutting-edge tech to keep operations running like clockwork. We don t just move the world forward we re proud to be recognized as a Great Place to Work by our employees and certified in most of our growing locations. Here, we feel empowered, supported, and inspired to grow. Are you ready to love your job? The adventure begins right here, with you, at SITA.
As Senior Security Analyst, you will perform advanced investigations and validation of security alerts and incidents to ensure accurate threat identification and effective response. You will play a key role in improving detection quality, monitoring effectiveness, and operational excellence across the Security Operations Center (SOC). You will be accountable for leading technical investigations, mentoring SOC Analysts, enhancing detection capabilities, and ensuring timely identification, analysis, escalation, and documentation of security incidents. Reporting to the Senior Manager, Service Operations, you will be part of the SOC Team, responsible for monitoring, detecting, investigating, and responding to cybersecurity threats across the enterprise while continuously improving SOC processes, tools, and capabilities.
Desired Candidate Profile
- You have 3-5 years of experience as a SOC L2 Analyst or in an equivalent Security Operations role.
- You possess advanced experience investigating security events using SIEM and EDR/XDR platforms, preferably Elastic, Cortex XDR, Microsoft Defender XDR, and CrowdStrike Falcon.
- You have experience analyzing logs and telemetry from endpoints, identity platforms, cloud services, firewalls, proxies, DNS, VPN, and applications.
- You have proven experience developing, tuning, and optimizing detection rules, correlation logic, and SOC use cases.
- You demonstrate a strong understanding of the incident investigation, triage, escalation, and response lifecycle.
- You are proficient in security query languages such as KQL, Lucene, EQL, and Sigma.
- You have working knowledge of PowerShell and/or Python for security investigations, automation, and operational efficiency.
- You possess solid knowledge of Windows, Linux, Active Directory, Microsoft 365, Azure/AWS, networking, and common attack techniques.
- You have strong practical knowledge of the MITRE ATT&CK framework and its application to detection engineering and security monitoring.
- You hold a Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field, along with at least one recognized cybersecurity certification such as SC-200, GCIH, GCIA, CySA+, or ECIH.
NICE-TO-HAVE
- Experience supporting Vulnerability Management activities, including vulnerability validation, risk prioritization, and remediation tracking.
- Experience participating in cyber simulations, red-team exercises, tabletop exercises, and post-incident reviews.
- Familiarity with security automation, orchestration technologies, and operational reporting for SOC performance metrics.