Senior SOC Analyst
Ciklum is looking for a Senior SOC Analyst to join our team full-time in the Czech Republic.
We are a custom product engineering company that supports both multinational organizations and scaling startups to solve their most complex business challenges. With a global team of over 4,000 highly skilled developers, consultants, analysts and product owners, we engineer technology that redefines industries and shapes the way people live.
About the role:
As a Senior SOC Analyst, become a part of a cross-functional development team engineering experiences of tomorrow. Upstream Security protects connected vehicles, mobility services, and their supporting digital ecosystems. Our AI-powered cybersecurity platform combines vehicle security, API security, threat intelligence, detection and response, and managed SOC services. We are looking for a Senior SOC Analyst to join Upstream’s managed cybersecurity services team. You will investigate and respond to cybersecurity incidents involving connected vehicles, mobility applications, backend services, and APIs. As a Senior Analyst, you will serve as a security focal point for customers, lead complex investigations, improve detection capabilities, and help deploy and maintain agentic AI workflows used across SOC operations. This is a full-time position.
Responsibilities:
- Monitor, investigate, and respond to vehicle and API security alerts
- Lead complex investigations, assess impact, identify root causes, and provide actionable mitigation recommendations
- Analyze suspicious vehicle behavior, API activity, authentication events, and mobility-related telemetry
- Investigate API threats including authorization abuse, credential attacks, injection, data exposure, automation, and business-logic abuse
- Deploy, configure, test, and maintain agentic AI workflows supporting alert triage, investigations, threat hunting, reporting, and response
- Monitor the accuracy, reliability, and operational performance of AI-driven workflows and continuously improve their prompts, tools, guardrails, and decision logic
- Conduct proactive threat hunting and OSINT investigations to identify emerging threats and attack patterns
- Develop and maintain investigation playbooks, operational procedures, and response processes
- Tune detection logic, behavioral profiles, and machine-learning models to improve detection quality and reduce false positives
- Produce clear investigation reports, incident updates, dashboards, and executive-level summaries
- Act as a trusted security advisor to customers during investigations, workshops, and business reviews
- Mentor analysts and promote consistent investigation quality across the SOC
- Track operational performance against SLAs, quality standards, and SOC KPIs
- Collaborate with threat intelligence
Requirements:
- 3+ years of experience in SOC operations, incident response, threat hunting, or security investigations
- Previous customer-facing analyst role, preferably within an MSSP, consulting, or professional services context, preferably in English
- Strong practical understanding of APIs, including REST, authentication, authorization, OAuth, and JWT
- Hands-on API security experience with technologies such as WAFs, API gateways, API security platforms, SIEM, Burp Suite, or similar tools
- Experience investigating common API threats, including account abuse, authorization flaws, injection, data exposure, and business-logic attacks
- Experience with SIEM, SOAR, XDR, security automation, and large-scale data analysis
- Experience deploying or maintaining automation, AI-assisted, or agentic AI workflows
- Scripting experience, preferably with Python or SQL
- Ability to lead complex investigations and operate effectively in high-pressure environments
- Fluent English
- Experience in automotive, mobility, IoT, cloud security, mobile application security, or managed security services is preferred
What’s in it for you?
- Flexible working hours
- Home office option
- 5 weeks of holiday
- 5 sick days
- Multisport Card
- Meal allowance
- Internal trainings including workshops and seminars
- Paid certifications and technical as well as soft-skills training
- Possibility to participate in international conferences
- Fresh fruit, coffee, and a weekly company breakfast in the office
- Loyalty bonus after 5, 10, 15 and more years with the company
- Referral bonus programme
- Corporate events including team building, outdoor activities, Christmas party, health week, summer ice cream, and more
- Hybrid and remote working options available across our Czech offices in Prague, Hradec Králové, and Zlín
About us:
At Ciklum, we are always exploring innovations, empowering each other to achieve more, and engineering solutions that matter. With us, you’ll work with cutting-edge technologies, contribute to impactful projects, and be part of a One Team culture that values collaboration and progress.
With delivery centers in Prague, Hradec Králové, and Zlín, our Czech team delivers end-to-end solutions across industries. Here, innovation thrives through collaboration, and every idea drives our partners' success.
Explore, empower, engineer with Ciklum!
Interested already? We would love to get to know you! Submit your application. We can’t wait to see you at Ciklum.
#LI-LS1