L1 SOC Analyst

Posted 21 hours ago

This is a fully remote position, open to applicants in Ukraine.

📋 Description

• Oversee and categorize incidents within Microsoft Sentinel and Microsoft Defender XDR based on severity.

• Assess alerts as true positives, false positives, or benign while documenting the rationale behind each classification.

• Examine the quarantine in Defender for Office 365 and manage user-reported phishing incidents.

• Make decisions to release or block quarantined content.

• Analyze message headers, SPF/DKIM/DMARC outcomes, URLs, and attachments.

• Execute pre-defined KQL queries in Advanced Hunting to identify affected users and assets.

• Implement containment measures as per runbook protocols, including revoking sessions, blocking sign-ins, isolating devices, and purging delivered messages.

• Escalate incidents that exceed the current scope, providing timelines, evidence, and actions taken.

• Maintain audit-ready case documentation and ensure smooth shift transitions.

• Recognize noisy detections and recurring false positives for fine-tuning purposes.

• Collaborate with the Cloud Security Engineer in a Microsoft-centric environment.


⛳️ Requirements

• Minimum of 1 year of experience in IT support, service desk, systems administration, or a security operations role.

• Candidates with relevant certifications and demonstrable lab experience may be considered even without commercial security experience.

• Familiarity with Microsoft 365 and a cloud-first or hybrid operational environment.

• Fundamental understanding of networking and mail flow concepts, including TCP/IP, DNS, SMTP, MX records, VPN, and firewall principles.

• Basic knowledge of Windows and macOS fundamentals, covering processes, logons, and log locations.

• Awareness of phishing, credential theft, MFA fatigue, token theft, and methods of malware delivery.

• Proficient in written and verbal English, with case notes and escalations documented in English.

• Ability to adhere to runbooks precisely, with the judgment to escalate issues early rather than improvising solutions.

• Practical experience with Microsoft Sentinel, Defender XDR, Defender for Office 365, or Entra ID.

• Capability to interpret and modify a KQL query or utilize basic PowerShell.

• Familiarity with the MITRE ATT&CK framework.

• Knowledge of NIST SP 800-171, CMMC 2.0, or GDPR is advantageous.


🏝️ Benefits

• Sponsored Microsoft certification path, with the SC-200 exam covered by KVG.

• Clear career progression from Level 1 triage to Level 2 analysis.

• Coverage during European business hours, with rotational extended-hours support for other regions; this is not a 24/7 shift rotation.

• Direct mentorship from the Cloud Security Engineer.

• Access to a single-vendor Microsoft security stack, including Sentinel, Defender XDR, Entra ID, Intune, and Purview.

People also viewed

KVG21 hours ago

L1 SOC Analyst

GE flagGeorgia OnlyFull-timeSecurity Operations
ApplyView job
Concentric22 hours ago

Program Manager, Security Operations

US flagArizona, +2 more statesFull-timeSecurity Operations$165k – $175k/year
ApplyView job
Samsara1 day ago

Senior Security Operations Engineer

US flagUnited States, +1 more countryFull-timeSecurity Operations$135.5k – $227.7k/year
ApplyView job
Axians Somnitec AG1 day ago

Security Operations Engineer – Microsoft Solutions

CH flagSwitzerland OnlyFull-timeSecurity Operations
ApplyView job
ASAAS1 day ago

Mid-Level SOC Analyst – Evening Shift

BR flagBrazil OnlyFull-timeSecurity Operations
ApplyView job
Motive1 day ago

Senior Manager, Security Operations

US flagUnited States OnlyFull-timeSecurity Operations$140k – $200k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers