Wursta logo

Lead Security Operations Analyst

Hiring from
El Salvador
Work type
Hybrid
Posted
Sep 29, 2026
Is this job info correct?

Wursta aims to help companies navigate complex technology landscapes, especially within AI, to help those companies to scale their capabilities, and increase productivity. We specialize in providing a range of services including cloud services, managed services, custom development, cybersecurity, and AI solutions, with a focus on enabling digital transformation.

Why Wursta?

At Wursta, we hire motivated, inspired people and give them autonomy, training, and resources to solve problems for our clients and deliver excellent results. We focus on generating value and are obsessed with internal and external improvement and growth. And our results speak for themselves; we are forging a new breed of consultants and technical experts in the enterprise cloud industry that combine strong technical know-how with ingenuity and effective process improvements.

This position is based in Quito, Ecuador or El Salvador in a hybrid environment.

About The Team

The Managed Security Services Operations (MSSP) Team functions as a Secure AI Augmented SOC, Software Engineering (AI Product Development), and Go-To-Market for Security services (Sales Enablement). This team functions within a specialized, cross-functional MSSP unit tailored for multi-tenant cloud environments (focusing on Google Workspace and Google Cloud Platform).

The team is structured to operate as a high-velocity, automation-first security team, moving away from traditional manual Level 1/Level 2 SOC escalation trees to an AI-driven, Tier-3 led model.

Key Responsibilities

The Lead Security Operations Analyst serves a dual-purpose operational and engineering role. As the primary tier-3 response authority and team lead, this individual oversees real-time threat monitoring, incident response, and SLA delivery across client tenants within the proprietary MSSP platform.

Simultaneously, this role acts as an AI Integration and Detection Engineer, leveraging modern AI development tools (e.g., Google Gemini and Anthropic Claude API) to architect automated escalation workflows and orchestrations, engineer high-fidelity detections, and integrate custom AI agents into the core MSSP application stack.

1. Security Monitoring & Incident Response (24/7 Operations Lead)

  • Threat Detection & Triage: Lead the operational triage, analysis, and prioritization of complex security events across multi-tenant client environments.

  • Incident Response Leadership: Function as the Incident Commander during critical security events, adhering strictly to NIST SP 800-61r2 (Computer Security Incident Handling Guide) to execute containment, eradication, and recovery strategies.

  • Threat Hunting & Detection Engineering: Utilize the MITRE ATT&CK Framework to map adversary tactics, techniques, and procedures (TTPs), proactive threat hunting, and writing custom correlation rules (e.g., Sigma, YARA).

  • Client Advisory & SLA Enforcement: Ensure all incident notifications and responses meet contractual Service Level Agreements (SLAs) and regulatory reporting timelines.

2. MSSP App Automation & AI Development

  • AI-Assisted Workflow Engineering: Utilize AI development environments and APIs to write clean, production-grade Python, Node.js, or Go code to extend the backend logic of the MSSP application.

  • Third Party Tool Integrations: As needed, build integrations to meet Client needs for monitoring other security solution telemetry such as EDR solutions (CrowdStrike, SentinalOne, Etc), DNS Security Alerts, Threat Intelligence (GTI, etc), SPAM/Phishing solutions, IDM solutions (Okta, Jumpcloud, etc), Firewall/IDS alerts, and other related monitoring needs.

  • Automated Escalation Playbooks: Design and build automated orchestration playbooks (SOAR) within the MSSP platform to execute dynamic triage, identity enrichment, and automatic tenant isolation.

  • LLM & AI Integration: Implement AI-driven alert summarize-and-enrichment pipelines using LLM frameworks (e.g., Gemini models for internal threat databases, BigQuery SIEM data lakes, and third-party APIs via REST webhooks to construct dynamic Retrieval-Augmented Generation (RAG) pipelines, and MCP servers) to provide context-rich incident tickets for analysts and end-clients.

  • Noise Reduction: Continuously optimize detection pipelines using machine learning and AI filters to reduce false positive alert volume.

3. Compliance, Governance & Multi-Tenant Architecture

  • Framework Alignment: Understanding of security monitoring controls directly to NIST CSF 2.0 (Detect/Respond), ISO/IEC 27001:2022 Control A.8.16 (Monitoring Activities), and NIST SP 800-53r5 controls (AU, IR, and SI families).

  • Data Privacy Compliance: Ensure incident response procedures and telemetry collection strictly adhere to EU GDPR (Article 33 notification obligations), Brazil LGPD, and US State Privacy Laws (CCPA/CPRA).

Required Skills

Candidates must have experience in at least one of the following for each category.

  • SIEM & XDR Platforms: Splunk, Microsoft Sentinel, Elastic SIEM, CrowdStrike Falcon, SentinelOne, Palo Alto Cortex XDR.

  • Network & Telemetry: Wireshark, Zeek, Suricata, PCAP analysis, Syslog, Windows Event Logs, CloudTrail/CloudWatch.

  • AI & Automation Tools: Python (Pandas, Requests), REST APIs, Cursor IDE, GitHub Copilot, Claude/OpenAI APIs, LangChain, Webhooks, Docker.

  • SOAR & Scripting: Python, PowerShell, Bash, Demisto/Cortex XSOAR, Shuffle, Tines.

  • Threat Frameworks: MITRE ATT&CK (Enterprise, Cloud), NIST SP 800-61r2, Cyber Kill Chain, YARA, Sigma Rules.

  • Cloud Environments: AWS, Azure, GCP security architectures, IAM, and log architectures.

Preferred Qualifications

  • 3+ years in a SOC or MSSP environment with at least 2+ years in a Level 3 / Lead SOC capacity.

  • Proven hands-on experience in scripting and API integration to build automated incident response playbooks.

  • Demonstrated proficiency using AI-assisted coding tools (e.g., Cursor, Copilot) to build, refactor, and deploy automation scripts and lightweight applications rapidly.

  • Expertise in log analysis across endpoint, identity (Okta, Azure AD), network, and multi-cloud environments.

Required Certifications, at least one of the following;

  • GIAC: GIAC Certified Incident Handler (GCIH), GIAC Continuous Monitoring & Security Operations (GMON), or GIAC Network Forensics Analyst (GNFA).

  • CompTIA / Offensive Security: CySA+, CASP+, or OSCP.


Preferred Certifications

  • ISC2: Certified Information Systems Security Professional (CISSP).

Interview Process

At Wursta, we're all about positive experiences and creating value. We move fast and adapt to change like nobody's business. Here's what you can expect:

  1. Work Style Survey: A brief survey to help us learn more about your work style.

  2. Initial Screen: A 20-30 minute chat with our hiring coordinator to see if we’re a good fit.

  3. Meet your Manager: A 45-minute deep dive into the role and team with the hiring manager.

  4. Meet your Peers: A 60-minute session with the team to see the dynamic and ask questions.

  5. Interview with Senior Leadership: A 45-minute conversation with an executive leader regarding skills and company vision.

  6. Get a Decision: We typically get back to you within the week regarding next steps.

Equal Employment Opportunity

Wursta provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

Similar jobs

Apply for this job