L2 SOC Analyst

6 часов назад


Киев, Киев, Украина Tietoevry Полный рабочий день 40 000 $ - 80 000 $ в год
Job Description

Tietoevry Create Ukraine is inviting a talented professional to join our team as a L2 SOC Analyst to join our Security Operations Center (SOC) team. The ideal candidate will have hands-on experience not only with Microsoft Sentinel but also with the broader Microsoft XDR stack, including Defender for Endpoint, Defender for Identity, Defender for Cloud, and Defender for Office 365. Familiarity with Microsoft 365 Defender portal and unified incident management is highly desirable.

Responsibilities:

  • Incident Analysis:
    • Perform real-time monitoring and analysis of security events and alerts from various security tools, including SIEM (Sentinel), Microsoft Defender Suite, Firewalls, IDS/IPS, WAFs, and other security logs.
    • Analyze telemetry from Microsoft Defender products (Endpoint, Identity, Cloud, Office 365) within Microsoft Sentinel.
    • Utilize Microsoft 365 Defender's unified incident queue to correlate alerts across Defender products.
    • Conduct in-depth investigations of escalated security incidents, performing root cause analysis to understand the full scope and impact.
    • Correlate data from multiple sources to identify suspicious activities, attack patterns, and potential threats.
    • Distinguish between false positives and true security incidents, prioritizing and escalating as necessary.
  • Incident Response & Remediation:
    • Execute incident response procedures, including containment, eradication, and recovery steps.
    • Leverage Microsoft Defender capabilities for containment and investigation.
    • Provide support during and lead security event investigations, collaborating with internal teams (IT, Network, Applications) and other stakeholders when required.
    • Document all activities during an incident, providing timely status updates and preparing comprehensive incident reports.
    • Recommend and assist in implementing corrective actions and security enhancements to prevent future occurrences.
  • Documentation & Reporting:
    • Maintain accurate and up-to-date documentation of security incidents, investigations, procedures (SOPs), and playbooks.
    • Generate regular security reports and metrics for management, highlighting key trends and security posture.
  • Mentoring & Collaboration:
    • Mentor and guide junior SOC analysts (L1) in their daily tasks, incident triage, and investigation techniques.
    • Share best practices for Microsoft XDR integration and use cases with junior analysts.
    • Collaborate effectively with other cybersecurity teams (e.g., L3 Analysts) and IT operations.
    • Participate in security awareness initiatives and knowledge sharing sessions.
  • Shift Work:
    • Work in a 24x7 rotational shift environment, including night shifts and weekends.

Required Skills & Qualifications:

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • 2-4 years of hands-on experience in a Security Operations Center (SOC) environment.
  • Strong, demonstrable experience with SIEM platforms, specifically Microsoft Sentinel and IBM QRadar, including:
    • Alert triage, investigation, and incident response.
    • Active incident response including containment, eradication, and recovery steps
    • Rule updates suggestion, creation, tuning, and optimization.
    • Reports generation.
  • In-depth understanding of cybersecurity concepts, including:
    • Network security (TCP/IP, firewalls, IDS/IPS, VPNs, proxies).
    • Endpoint security.
    • Cloud security principles (AWS, Azure, GCP).
    • Common attack vectors, threat actor TTPs, and the MITRE ATT&CK framework.
  • Proficiency in analyzing various log types (Windows event logs, Linux logs, network device logs, application logs).
  • Experience with other security tools such as EDR solutions (e.g., Microsoft Defender for Endpoint, CrowdStrike), vulnerability scanners, and threat intelligence platforms.
  • Familiarity with scripting languages (e.g., Python, PowerShell) for automation and analysis is a plus.
  • Excellent analytical, problem-solving, and critical thinking skills.
  • Strong written and verbal communication skills to effectively articulate technical issues to both technical and non-technical audiences.
  • Intermediate level of English is a minimum.
  • Ability to work independently and as part of a team in a fast-paced environment.

The following Certifications would be an advantage:

  • Microsoft Certified: Azure Security Engineer Associate (AZ-500)
  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • Microsoft Certified: Microsoft Identity and Access Administrator Associate (SC-300)
  • GIAC Certified Detection Analyst (GCDA)
  • CompTIA Cybersecurity Analyst (CySA+)
  • IBM Certified Deployment Professional - Security QRadar SIEM
Additional Information

At Tietoevry, we believe in the power of diversity, equity, and inclusion. We encourage applicants of all backgrounds, genders (m/f/d), and walks of life to join our team, as we believe that this fosters an inspiring workplace and fuels innovation. Our commitment to openness, trust, and diversity is at the heart of our mission to create digital futures that benefit businesses, societies, and humanity.

Diversity, equity and inclusion )


  • L2 SOC Analyst

    6 часов назад


    Киев, Киев, Украина Tietoevry Полный рабочий день 40 000 ₴ - 80 000 ₴ в год

    Job DescriptionTietoevry Create Ukraine is inviting a talented professional to join our team as a L2 SOC Analyst to join our Security Operations Center (SOC) team. The ideal candidate will have hands-on experience not only with Microsoft Sentinel but also with the broader Microsoft XDR stack, including Defender for Endpoint, Defender for Identity, Defender...

  • L1 SOC Analyst

    6 часов назад


    Киев, Киев, Украина Tietoevry Полный рабочий день 30 000 ₴ - 60 000 ₴ в год

    Job Description Tietoevry Create Ukraine is inviting a talented professional to join our team as a L1 SOC Analyst to join our Security Operations Center (SOC) team. The ideal candidate will play a critical role in detecting, analyzing, and responding to cybersecurity threats and incidents. This position requires strong analytical skills, in-depth...

  • L1 SOC Analyst

    7 часов назад


    Киев, Киев, Украина Tietoevry Полный рабочий день 40 000 ₴ - 80 000 ₴ в год

    Job DescriptionTietoevry Create Ukraine is inviting a talented professional to join our team as a L1 SOC Analyst to join our Security Operations Center (SOC) team. The ideal candidate will play a critical role in detecting, analyzing, and responding to cybersecurity threats and incidents. This position requires strong analytical skills, in-depth knowledge of...

  • Information Security Analyst

    2 недель назад


    Киев, Киев, Украина Atlas Technica Полный рабочий день 1 200 000 ₴ - 2 400 000 ₴ в год

    Position Name: Information Security Analyst Reports to: Chief Information Security Officer Location/Type: Remote Atlas Technica's mission is to shoulder IT management, user support, and cybersecurity for our clients, who are hedge funds and other investment firms. Founded in 2016, we have grown 100% year over year through our uncompromising focus on...

  • Information Security Analyst

    6 часов назад


    Киев, Киев, Украина Atlas Technica Полный рабочий день 90 000 ₴ - 120 000 ₴ в год

    Position Name: Information Security Analyst Reports to: Chief Information Security Officer Location/Type: Remote (UA Candidates only)Atlas Technica's mission is to shoulder IT management, user support, and cybersecurity for our clients, who are hedge funds and other investment firms. Founded in 2016, we have grown year over year through our uncompromising...

  • Security Operations Center Analyst

    2 недель назад


    Киев, Киев, Украина Sharkscode Полный рабочий день 600 000 ₴ - 1 200 000 ₴ в год

    У світі, де кіберзагрози стають дедалі складнішими, роль SOC Analyst має ключове значення. Ми шукаємо ентузіаста кібербезпеки, який хоче не просто реагувати на інциденти, а бути на передовій боротьби з...

  • PolyTECH Summit

    6 дней назад


    Киев, Киев, Украина Ajax Systems Полный рабочий день 300 000 ₴ - 600 000 ₴ в год

    Ajax Systems — міжнародна технологічна компанія і найбільший у Європі виробник систем безпеки. Продуктам Ajax довіряють уже понад 4 мільйони кінцевих користувачів і 290 тисяч PRO-користувачів у 187 країнах...

  • PolyTECH Summit

    6 дней назад


    Киев, Киев, Украина Ajax Systems Полный рабочий день 300 000 ₴ - 600 000 ₴ в год

    Ajax Systems — міжнародна технологічна компанія і найбільший у Європі виробник систем безпеки. Продуктам Ajax довіряють уже понад 4 мільйони кінцевих користувачів і 290 тисяч PRO-користувачів у 187 країнах...

  • Cybersecurity Engineer

    1 неделя назад


    Киев, Киев, Украина MODUS X Полный рабочий день 60 000 ₴ - 80 000 ₴ в год

    Станьте частиною команди, що створює цифрову реальністьMODUS X— українська ІТ-компанія, команда 650+ досвідчених спеціалістів — розширюємо горизонти можливостей бізнесу, розкриваючи потенціал...


  • Киев, Киев, Украина Tietoevry Полный рабочий день 40 000 ₴ - 80 000 ₴ в год

    Job DescriptionWe are looking for a motivated and detail-oriented cybersecurity professional to join our team as a Threat Intelligence and Vulnerability Management Engineer. This role focuses on supporting the identification and mitigation of threats and vulnerabilities using Microsoft Defender Vulnerability Management and Nexpose Rapid7. You'll work closely...