
L1 SOC Analyst
Posted 21 hours ago

Posted 21 hours ago
This is a fully remote position, open to applicants in Ukraine.
• Oversee and categorize incidents within Microsoft Sentinel and Microsoft Defender XDR based on severity.
• Assess alerts as true positives, false positives, or benign while documenting the rationale behind each classification.
• Examine the quarantine in Defender for Office 365 and manage user-reported phishing incidents.
• Make decisions to release or block quarantined content.
• Analyze message headers, SPF/DKIM/DMARC outcomes, URLs, and attachments.
• Execute pre-defined KQL queries in Advanced Hunting to identify affected users and assets.
• Implement containment measures as per runbook protocols, including revoking sessions, blocking sign-ins, isolating devices, and purging delivered messages.
• Escalate incidents that exceed the current scope, providing timelines, evidence, and actions taken.
• Maintain audit-ready case documentation and ensure smooth shift transitions.
• Recognize noisy detections and recurring false positives for fine-tuning purposes.
• Collaborate with the Cloud Security Engineer in a Microsoft-centric environment.
• Minimum of 1 year of experience in IT support, service desk, systems administration, or a security operations role.
• Candidates with relevant certifications and demonstrable lab experience may be considered even without commercial security experience.
• Familiarity with Microsoft 365 and a cloud-first or hybrid operational environment.
• Fundamental understanding of networking and mail flow concepts, including TCP/IP, DNS, SMTP, MX records, VPN, and firewall principles.
• Basic knowledge of Windows and macOS fundamentals, covering processes, logons, and log locations.
• Awareness of phishing, credential theft, MFA fatigue, token theft, and methods of malware delivery.
• Proficient in written and verbal English, with case notes and escalations documented in English.
• Ability to adhere to runbooks precisely, with the judgment to escalate issues early rather than improvising solutions.
• Practical experience with Microsoft Sentinel, Defender XDR, Defender for Office 365, or Entra ID.
• Capability to interpret and modify a KQL query or utilize basic PowerShell.
• Familiarity with the MITRE ATT&CK framework.
• Knowledge of NIST SP 800-171, CMMC 2.0, or GDPR is advantageous.
• Sponsored Microsoft certification path, with the SC-200 exam covered by KVG.
• Clear career progression from Level 1 triage to Level 2 analysis.
• Coverage during European business hours, with rotational extended-hours support for other regions; this is not a 24/7 shift rotation.
• Direct mentorship from the Cloud Security Engineer.
• Access to a single-vendor Microsoft security stack, including Sentinel, Defender XDR, Entra ID, Intune, and Purview.
Concentric
Samsara
Axians Somnitec AG
Get handpicked remote jobs straight to your inbox weekly.