L1 SOC Analyst

Job not on LinkedIn

🔥 3 minutes ago

🇺🇦 Ukraine – Remote

⏳ Contract/Temporary

🟢 Junior

🛡️ Security Operations

🚫👨‍🎓 No degree required

👻 Ghost score 12%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of KVG

KVG

51 - 200 employees

💼 Consulting

🎖️ Defense

📦 Logistics

Consulting • Defense • Logistics

KVG is a globally positioned and locally integrated company providing a vast array of products and services including home store and office accessories, batteries, chargers, ergonomic office supplies, technology and office equipment, and computer and tablet accessories. They also offer complex program management, troop and mission support, and procurement solutions. Additionally, KVG delivers logistics and support through services such as air charter, hotel and lodging, internet and mobile data services, linehaul services, and facility supplies. KVG is committed to system integration, sourcing, and delivering solutions that meet a wide spectrum of customer needs.

📋 Description

• Monitor and triage incidents in Microsoft Sentinel and Microsoft Defender XDR by severity • Classify alerts as true positives, false positives, or benign and document the reasoning • Review Defender for Office 365 quarantine and handle user-reported phishing • Make release or block decisions for quarantined content • Analyze message headers, SPF/DKIM/DMARC results, URLs, and attachments • Run pre-built KQL queries in Advanced Hunting to determine affected users and assets • Apply runbook-defined containment, including revoking sessions, blocking sign-in, isolating devices, and purging delivered messages • Escalate incidents beyond the mandate with timelines, evidence, and actions taken • Maintain audit-ready case records and conduct clean shift handovers • Identify noisy detections and recurring false positives for tuning • Work alongside the Cloud Security Engineer in a Microsoft-based environment

🎯 Requirements

• 1+ year in IT support, service desk, systems administration, or a security operations role • Strong candidates with certifications and demonstrable lab work may be considered without commercial security experience • Working knowledge of Microsoft 365 and a cloud-first or hybrid environment • Networking and mail flow fundamentals: TCP/IP, DNS, SMTP, MX records, VPN, and firewall concepts • Windows and macOS fundamentals, including processes, logons, and log locations • Understanding of phishing, credential theft, MFA fatigue, token theft, and malware delivery • Professional written and verbal English; case notes and escalations are written in English • Discipline to follow runbooks exactly and judgement to escalate early rather than improvise • Hands-on exposure to Microsoft Sentinel, Defender XDR, Defender for Office 365, or Entra ID • Ability to read and adapt a KQL query or use basic PowerShell • Familiarity with MITRE ATT&CK • Awareness of NIST SP 800-171, CMMC 2.0, or GDPR

🏖️ Benefits

• Funded Microsoft certification path, with the SC-200 exam paid by KVG • Defined progression route from L1 triage to L2 analysis • European business-hours coverage with rotational extended-hours support for other regions; not a 24/7 shift rotation • Direct mentoring from the Cloud Security Engineer • Single-vendor Microsoft security stack: Sentinel, Defender XDR, Entra ID, Intune, and Purview

Apply Now

Similar Jobs

🕒 May 29

SupportYourApp

1001 - 5000

💼 Consulting

📦 Logistics

📣 Marketing

Security Incident Response Specialist at SupportYourApp managing security incidents and investigations. Collaborating with clients to enhance security processes and responses.

🗣️🇺🇦 Ukrainian Required