Tenarai
Tenarai
New

Security Analyst

130 - 150 PLN/ godz.
MidFull-time
#400040·Dodano wczoraj·0
Źródło: Tenarai
Aplikuj teraz

Tech Stack / Keywords

SecurityArchitectureCloudSIEMMicrosoft AzureAzureNetworkScripting

Firma i stanowisko

Tenarai is recruiting an experienced Level 2 (L2) Security Operations Center (SOC) Analyst to join the team focused on advanced incident investigation and threat containment using Microsoft Sentinel, Microsoft Defender XDR, and SentinelOne. The role involves deep analysis of security anomalies, endpoint detection and response, and collaboration with Level 1 analysts.

Wymagania

  • 2–4 years' experience in enterprise or MSSP Security Operations Center focusing on tier-2 incident response.
  • Proficient with Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender suite, including log architecture and workbook creation.
  • Advanced skills in Kusto Query Language (KQL) for data parsing, log analysis, and threat hunting.
  • Hands-on experience with SentinelOne (Singularity) and Microsoft Defender for Endpoint features like Ranger and Deep Visibility.
  • Familiarity with MITRE ATT&CK framework for attacker behavior mapping.
  • Proficiency in PowerShell, Python, or Bash for log parsing, API interaction, and automation.
  • Strong basic networking knowledge including TCP/IP stack, packet capturing, and NextGen Firewalling.

Nice to have:

  • Bachelor's Degree in Cybersecurity, Computer Science, or related field.
  • Microsoft Certified: Security Operations Analyst Associate (SC-200) or Azure Security Engineer Associate (AZ-500).
  • SentinelOne Certified Professional or Incident Responder certification.
  • GIAC Certified Incident Handler (GCIH), Forensic Analyst (GCFA), or CompTIA Cybersecurity Analyst (CySA+).

Obowiązki

  • Analyze and validate high-priority alerts escalated by L1 analysts using Microsoft Sentinel and Defender XDR.
  • Correlate data from Azure AD, Microsoft 365, network firewalls, On-prem AD, SaaS services, and multi-cloud logs to assess incident scope and impact.
  • Investigate malicious host behaviors with SentinelOne and Microsoft Defender for Endpoint, including live response forensics.
  • Execute containment playbooks isolating compromised endpoints, revoking cloud sessions, and blocking malicious IOCs.
  • Author, refine, and optimize Microsoft Sentinel Analytics Rules and threat hunting queries using Kusto Query Language (KQL).
  • Build and modify automated response logic apps and playbooks within Microsoft Sentinel to improve mean time to respond.
  • Provide technical guidance and escalation support to Level 1 analysts.

Benefity

  • Remote or hybrid work model.
  • Attractively located office with collaboration spaces.
  • Onsite parking space.
  • Referral program with financial bonus.
  • Life insurance.
  • Development budget including language courses.
  • Access to internal learning platform with professional growth trainings.
  • Access to MyBenefit platform including Multisport subscription.
  • Team building activities and charity initiatives.
  • Inclusive work environment.
  • Private medical care - Platinum Package.
Pakiet relokacyjny
Opieka zdrowotna
Ubezpieczenie
Dofinansowanie szkoleń
Kursy językowe
Karta sportowa
Premie

Inne informacje

Must possess a legal work permit in Poland.

Tenarai

Tenarai

Pracodawca

Aplikuj teraz