Security Operations Administrator at Metrosys | Torre

Security Operations Administrator

Emma highlights
This highlight was written by Emma’s AI. Ask Emma to edit it.
Freelance
Recurrent
Provide your expected compensation while applying
location_on
Remote (anywhere)
Shared by
Emma of Torre.ai
8 days ago

Responsibilities


MetroSys is seeking a dependable and detail-oriented Security Operations Administrator for a short-term contract engagement supporting a client’s security monitoring and response operations. This role is responsible for reviewing, triaging, documenting, and responding to alerts generated across the client’s security platforms and infrastructure environment.The ideal candidate has hands-on experience with endpoint security, email security, identity-related alerts, and incident response workflows, and can work independently while coordinating with help desk and infrastructure teams as needed.This role is structured around a daily operational review window (~2 hours per day) while supporting a 24/7 alerting environment.Key ResponsibilitiesReview and respond to security alerts and tickets generated from the client’s monitoring and security platformsInvestigate and triage alerts related to:Endpoint security eventsEmail threats and phishing activitySuspicious authentication attemptsFirewall and network security eventsPerform incident response activities including:DocumentationInitial remediation actionsEscalation and coordinationPost-mortem reportingValidate email and phishing-related incidents using:MimecastKnowBe4 / PhishER / PhishRip workflowsMonitor and respond to endpoint alerts within:Sophos EDR/XDRSophos Intercept X AdvancedInvestigate identity and authentication alerts from Microsoft environments, including:Sign-in risk eventsSuspicious token or authorization activityIP/location anomaliesSupport security investigations involving:Sophos firewall alertsFortinet networking environmentsMFA and authentication platforms (including YubiKey environments)Coordinate with client help desk and infrastructure teams for remediation support and escalation handlingMaintain accurate documentation of incidents, actions taken, and recommendationsRequired Qualifications3+ years of experience in security administration, SOC operations, or security incident responseHands-on experience with:MimecastKnowBe4 / phishing remediation workflowsSophos EDR/XDR and Intercept XMicrosoft 365 security and sign-in risk analysisUnderstanding of:Security incident response workflowsEndpoint and network security conceptsIdentity and access management fundamentalsExperience reviewing and analyzing security alerts and event dataStrong documentation and communication skillsAbility to work independently and manage daily operational responsibilities efficiently