← Back to jobs

Remote job

Security Operations Analyst (L1)

Other Full-time Permanent Europe

Job details

Not specified Salary
Europe Eligibility
Intern Experience
Full-time Employment

About this role

Role overview Join a fintech security operations team as an entry-level analyst responsible for triaging incoming alerts and performing first-pass investigations. The role is full-time, remote, and sits at the front line of a modern SOC, working closely with senior analysts and an incident response function. Day-to-day work is structured around approved playbooks, case documentation, and clean handovers.

Responsibilities - Monitor prioritized alert queues and decide whether each alert represents real risk. - Enrich cases by correlating endpoint, identity, authentication, network, service, asset, user, timeline, and business context. - Run initial investigations, classify alerts, estimate severity and scope, and document the reasoning inside a case-management system. - Close confirmed false positives and execute only the low-risk actions explicitly allowed by runbooks. - Escalate suspected incidents, privileged-account issues, and high-impact cases to L2, the team lead, or the incident response team. - Maintain clear handover notes and contribute feedback that improves case quality and runbook accuracy.

Requirements - Hands-on exposure to security alert triage through work, an internship, or a lab, including use of at least one SIEM and familiarity with EDR or XDR. - Ability to build basic searches in a SIEM language such as KQL or EQL and correlate activity across multiple data sources. - Comfort interpreting endpoint, identity, authentication, network, DNS, HTTP, and cloud audit telemetry at an initial-investigation level. - Working knowledge of Windows and Linux, TCP/IP, DNS, HTTP, authentication, access control, and common attack patterns like phishing, credential abuse, and malware execution. - Sound judgment on what counts as a true positive, false positive, or benign activity, and when something needs escalation. - Familiarity with indicators of compromise, basic threat-intelligence sources, and the MITRE ATT&CK framework.

Nice to have - Light scripting in Python or PowerShell to support investigations and enrichment. - Exposure to cloud, email-security, or SaaS audit logs and standard phishing-investigation workflows. - Completion of a cybersecurity lab track or an entry-level certification such as Security+ or CySA+. - Experience working with macOS.

Benefits and work setup - Remote-first arrangement with structured onboarding. - Tax-expense coverage and dedicated support for private entrepreneurs based in Ukraine. - 20 paid vacation days, 10 paid sick-leave days, and an approved public holiday calendar. - Medical insurance, plus budgets for professional education, language learning, and wellness.

Skills detected in the listing

PythonInformation Security
Detected Sep 16, 2026
Last verified Sep 16, 2026

Hidden Jobs Access

Unlock application links

Read the full job details for free. An active Hidden Jobs Access subscription is required to open the original application link.

Weekly

FREE $6.99/week after trial
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
  • Cancel anytime before day 7

Monthly

$35.99 $17.99 /month
  • 35% cheaper than weekly
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching

Lifetime

$99.99 $49.99 /forever
  • One-time payment
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
Hidden Jobs gives subscribers direct access to original application links
Offer ends in 00:00:00 Your profile-fit rate expires at midnight