SOC Analyst

Вакансії
PLWarsaw1 Rondo Daszyńskiego00-843

Summary

Andersen is hiring a SOC Analyst for a project providing cybersecurity services, monitoring security threats, and protecting critical systems in a complex international environment.

The customer is a large international organization that relies on modern technology and digital solutions to support its operations. Its activities involve secure IT infrastructure, data management, digital services, and the adoption of emerging technologies to improve operational efficiency and reliability.

The project is focused on providing cybersecurity and digital services for international organizations within a complex multi-tenant environment. It includes cyber defense operations, security incident management, and continuous protection of critical systems and services to ensure secure and reliable operations worldwide.

Responsibilities

  • Investigating alerts escalated from L1/L2 across endpoint, network, email and identity.
  • Deciding whether alerts are true incidents, assess scope and escalate confirmed incidents to Incident Response.
  • Investigating email and identitying threats in Microsoft 365 and Entra ID (phishing, suspicious sign-ins, account compromise).
  • Proposing detection tuning and new use cases to the SIEM team, based on investigation findings.
  • Writing detailed case notes and periodic reports.
  • Taking part in shifts and on-call rotation as defined in the request.

Requirements

  • Experience in cybersecurity for 4+ years, including 1-2 years in a SOC at Tier 2 level.
  • Hands-on work with at least one major SIEM (Microsoft Sentinel, Splunk, QRadar or Elastic) and at least one EDR/XDR tool.
  • Investigation skills across endpoint, network, email and identity (including Microsoft 365 and Entra ID).
  • Writing queries in KQL, SPL or equivalent.
  • Working knowledge of MITRE ATT&CK and common attack techniques.
  • Readiness for shift work and on-call rotation.
  • Clean record, ready for background verification.
  • Level of English – from Upper-Intermediate and above.

Desired skills

  • Certifications: CySA+, SC-200, BTL1/BTL2, GCIH.
  • Threat hunting experience.
  • MSSP or multi-tenant SOC experience.
  • SOAR experience.
  • Network traffic analysis (Wireshark, Zeek, IDS/IPS).
  • Scripting in Python or PowerShell.

Reasons to join us

  • Experience in teamwork with leaders in FinTech, Healthcare, Retail, Telecom, and others. Andersen cooperates with such businesses as Samsung, Siemens, Johnson & Johnson, BNP Paribas, Ryanair, Mercedes, TUI, Verivox, Allianz, T-Systems, etc..
  • The opportunity to change the project and/or develop expertise in an interesting business domain.
  • Guarantee of professional, financial, and career growth! The company has introduced systems of mentoring and adaptation for each new employee.
  • The opportunity to earn up to an additional 1,000 EUR per month, depending on the level of expertise, which will be included in the annual bonus, by participating in the company's activities.
  • Access to the corporate training portal, where the entire knowledge base of the company is collected and which is constantly updated.
  • Bright corporate life (parties / pizza days / PlayStation / fruits / coffee / snacks / movies).
  • Certification compensation (AWS, PMP, etc).
  • Referral program.
  • Private health insurance and sports compensation, depending on the type of employment.

Join us!

Локації

Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Hungary, Italy, Latvia, Lithuania, Luxembourg, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, The Netherlands

Будемо раді бачити вас!

Прикріпити файл

Формати (3 MB): doc, docx, pdf, ppt, pptx

або Порекомендувати друга

Ми обробляємо персональні дані відповідно до GDPR

Шукаєте нові можливості для розвитку? Ознайомтеся з відкритими позиціями в Andersen просто зараз