← Усі вакансії

Security Operations Analyst (L1)

JustMarkets Tech, Київ, за кордоном
Формат:
повний remote
Джерело:
jobs.dou.ua
Відгукнутись на вакансію →

Що робити

  • Monitor prioritized alert queues and validate whether alerts indicate real risk
  • Enrich cases and correlate relevant endpoint, identity, authentication, network, service, asset, user, timeline, and business context
  • Perform initial investigations, classify alerts, assess preliminary severity and scope, and document the evidence and reasoning in the case-management system
  • Close false positives and execute approved low-risk actions only through defined runbooks
  • Escalate suspected incidents, privileged-account issues, and high-impact or production-impact cases to L2, the manager, or Incident Response

Що очікуємо

  • Hands-on experience with security alert triage through work, an internship, or a practical lab, including use of at least one SIEM and exposure to EDR or XDR and case-management workflows
  • Ability to build basic searches or queries, filter security events, and correlate related activity across more than one data source (Experience with basic SIEM query languages such as KQL, EQL)
  • Ability to interpret common endpoint, identity, authentication, network, DNS, HTTP, and service or cloud audit telemetry at an initial-investigation level
  • Working fundamentals of Windows and Linux, TCP/IP, DNS, HTTP, authentication, access control, and common attack patterns such as phishing, credential abuse, malware execution, and suspicious account activity
  • Ability to distinguish true positives, false positives, and benign activity; assign a preliminary severity; identify affected users or assets; and recognize when scope or impact is uncertain

Схожі вакансії

З блогу Trackr

Усі статті →

Знайдено через trackr.help/jobs · Канал: @trackrhelp · Бот для персональних сповіщень: @trackrhelpBot