Saviynt's AI-powered identity platform manages and governs human and non-human access to all of an organization's applications, data, and business processes. Customers trust Saviynt to safeguard their digital assets, drive operational efficiency, and reduce compliance costs. Built for the AI age, Saviynt is today helping organizations safely accelerate their deployment and usage of AI. Saviynt is recognized as the leader in identity security, with solutions that protect and empower the worldβs leading brands, Fortune 500 companies and government institutions. For more information, please visitΒ www.saviynt.com.
What You Will Be Doing
Real-Time Monitoring & Triage
β Act as the first line of defense by continuously monitoring Jira tickets from security alerts on our SIEM, EDR, cloud, and email security platforms.
β Perform initial triage of alerts to identify their priority, severity, and potential impact based on pre-defined criteria.
β Follow documented Standard Operating Procedures (SOPs) to investigate, validate, and categorize alerts as true positives or false positives.
Alert Escalation & Documentation
β Escalate all validated security incidents and potential threats to L2 Analysts for in-depth investigation and response.
β Accurately and meticulously document all triage steps, findings, and communications in our incident management system/ticketing tool.
β Assist in creating and updating basic reports on alert volumes and common incidents.
Using Automation & Security Tools
β Utilize pre-built automation playbooks (SOAR) to enrich alerts with threat intelligence and contextual data to aid in triage.
β Operate core security tools to gather initial data for investigations (e.g., check firewall logs, query EDR for process history, look up domain reputation).
β Monitor cloud security dashboards (AWS, Azure) for high-priority alerts and common
misconfigurations, escalating as needed.
Collaboration & Shift Handovers
β Communicate effectively with the team during shift handovers, ensuring a smooth transition of open alerts and ongoing issues.
β Stay current with common attack vectors (e.g., phishing, malware) and basic threat intelligence.
β Identify and report on security tool issues or alerts that are generating a high number of false positives.
What You Bring
β Bachelorβs degree in Computer Science, Information Security, or a related field, or equivalent practical experience/certifications.
β Willingness and ability to work in a 24/7 rotational shift environment (morning, afternoon, and night).
β 0-2 years of experience in an IT, network operations, or security operations role.
β Core Skills: Excellent attention to detail, strong analytical-thinking, and clear written and verbal communication skills.
β Technical Fundamentals: A basic understanding of networking (TCP/IP), cloud security (AWS, Azure), AI and security fundamentals (malware, phishing, firewalls).
β Cloud Familiarity: Familiarity with core cloud concepts (AWS, Azure, or GCP) is highly desirable.
β Eagerness to Learn: A strong desire to learn and work with security automation (SOAR) platforms, SIEM, and EDR tools.
β Preferred certifications: CompTIA Security+, Network+, or equivalent foundational
security certifications.
Why Join Us
β Be at the forefront of a modern, cloud-focused Security Operations Center.
β Receive excellent training and mentorship to build a career in cybersecurity.
β Gain foundational experience with cutting-edge cloud security, automation, and threat intelligence technologies.
β A clear career path for growth into L2, L3, and other senior security roles.
If required for this role, you will:
- Complete security & privacy literacy and awareness training during onboarding and annually thereafter
- Review (initially and annually thereafter), understand, and adhere to Information Security/Privacy Policies and Procedures such as (but not limited to):
> Data Classification, Retention & Handling Policy
> Incident Response Policy/Procedures
> Business Continuity/Disaster Recovery Policy/Procedures
> Mobile Device Policy
> Account Management Policy
> Access Control Policy
> Personnel Security Policy
> Privacy Policy
Saviynt is an amazing place to work. We are a high-growth, Platform as a Service company focused on Identity Authority to power and protect the world at work. You will experience tremendous growth and learning opportunities through challenging yet rewarding work which directly impacts our customers, all within a welcoming and positive work environment. If you're resilient and enjoy working in a dynamic environment you belong with us!
Saviynt is an equal opportunity employer and we welcome everyone to our team.Β All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.