Remote job
Security Operations Analyst (L1)
Job details
About this role
Role overview Join a fintech security operations team as an entry-level analyst responsible for triaging incoming alerts and performing first-pass investigations. The role is full-time, remote, and sits at the front line of a modern SOC, working closely with senior analysts and an incident response function. Day-to-day work is structured around approved playbooks, case documentation, and clean handovers.
Responsibilities - Monitor prioritized alert queues and decide whether each alert represents real risk. - Enrich cases by correlating endpoint, identity, authentication, network, service, asset, user, timeline, and business context. - Run initial investigations, classify alerts, estimate severity and scope, and document the reasoning inside a case-management system. - Close confirmed false positives and execute only the low-risk actions explicitly allowed by runbooks. - Escalate suspected incidents, privileged-account issues, and high-impact cases to L2, the team lead, or the incident response team. - Maintain clear handover notes and contribute feedback that improves case quality and runbook accuracy.
Requirements - Hands-on exposure to security alert triage through work, an internship, or a lab, including use of at least one SIEM and familiarity with EDR or XDR. - Ability to build basic searches in a SIEM language such as KQL or EQL and correlate activity across multiple data sources. - Comfort interpreting endpoint, identity, authentication, network, DNS, HTTP, and cloud audit telemetry at an initial-investigation level. - Working knowledge of Windows and Linux, TCP/IP, DNS, HTTP, authentication, access control, and common attack patterns like phishing, credential abuse, and malware execution. - Sound judgment on what counts as a true positive, false positive, or benign activity, and when something needs escalation. - Familiarity with indicators of compromise, basic threat-intelligence sources, and the MITRE ATT&CK framework.
Nice to have - Light scripting in Python or PowerShell to support investigations and enrichment. - Exposure to cloud, email-security, or SaaS audit logs and standard phishing-investigation workflows. - Completion of a cybersecurity lab track or an entry-level certification such as Security+ or CySA+. - Experience working with macOS.
Benefits and work setup - Remote-first arrangement with structured onboarding. - Tax-expense coverage and dedicated support for private entrepreneurs based in Ukraine. - 20 paid vacation days, 10 paid sick-leave days, and an approved public holiday calendar. - Medical insurance, plus budgets for professional education, language learning, and wellness.