- Location
- Costa Rica
- Workplace
- Remote
- Type
- Full-time
- Experience
- 5+ years
- Education
- Bachelor
- Source
- Pinpoint
Description
Strategic Services Analyst
Department: Threat Management: Strategic Services
Employment Type: Full Time
Location: Costa Rica
Description
You will act as a trusted advisor to assigned clients — leading briefings on detection posture and program performance, guiding incident response strategy, and ensuring the SIEM and detection engineering work happening behind the scenes ties back to each client's business goals. You'll collaborate closely with the SOC and internal detection engineering teams, but your primary accountability is the client relationship and the strategic value of their security program.
Key Responsibilities
- Serve as the primary strategic point of contact for assigned clients, building trusted-advisor relationships with client security stakeholders.
- Design, develop, and tune detection logic and use cases within client SIEM platforms, closing detection gaps identified through Cyber Threat Intelligence review.
- Lead regular briefings with client leadership on detection coverage, incident trends, and overall program maturity.
- Develop and refine incident response playbooks and procedures in partnership with client security teams.
• Conduct threat-hunting activities across client SIEM and EDR data to proactively surface sophisticated adversary activity. - Use frameworks such as MITRE ATT&CK to assess detection coverage and categorize threat actor TTPs for client audiences.
- • Partner with the SOC and internal Detection Engineering teams on escalations, ensuring client-specific detection content stays current.
• Generate and present metrics and reporting on incident response activity, detection coverage, and program trends for client leadership.
• Provide guidance on malware and forensic findings, translating technical analysis into clear recommendations for client teams.
• Drive continuous improvement of clients' detection engineering and SIEM content, staying current on emerging threats and vulnerabilities.
Skills Knowledge and Expertise
- 5+ years of experience in cybersecurity, including hands-on work with SIEM platforms (e.g., Splunk, Microsoft Sentinel, QRadar, Elastic).
- At least one year of experience in a SOC analyst or detection engineering role.
- Strong log analysis skills and previous experience writing or tuning detection logic.
- Working knowledge of MITRE ATT&CK and cloud-based technologies.
- Excellent client-facing communication skills, both written and verbal.
- This is a client-facing role requiring comfort presenting to non-technical stakeholders and client leadership.
- Bachelor's degree in Cybersecurity, Computer Science, or related field, or equivalent practical experience.
- Familiarity with a variety of SIEM tools beyond your primary platform, plus proficiency in EDR and NDR tooling.
- Experience with threat hunting and data engineering.
- Knowledge of scripting languages such as Python, PowerShell, or Bash for automation and analysis.
- Prior experience in a client-facing advisory, consulting, or managed services role.
- Familiarity with regulations and standards such as HIPAA, GDPR, and NIST frameworks.
- Certifications such as GIAC Certified Incident Handler (GCIH), CISSP, CISM, CEH, or equivalent advanced security certifications.
Why DeepSeas?
- We are client obsessed.
- We stand in solidarity with our teammates.
- We prioritize personal health and well-being.
- We believe in the power of diversity.
- We solve hard problems at the speed of cyber.
Information security is everyone’s responsibility:
- Understanding and following DeepSeas’s information security policies and procedures.
- Remaining vigilant and reporting any suspicious activity or possible weaknesses in DeepSeas’s information security.
- Actively participating in DeepSeas’s efforts to maintain and improve information security.
- DeepSeas considers this position is as Moderate Risk with a potential to view/access/download restricted/private client/internal data.
- This information must be treated with sensitivity and in the most secure manner.
- HR reserves the right to perform random background/drug screens to ensure the safety of client/DeepSeas data