SOC Analyst (L1/L2)

UnderDefense LLC

Warszawa

On-site

PLN 120,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

UnderDefense is seeking a sharp SOC Analyst (L1/L2) based in Warsaw to join a dedicated security operations team embedded with a Fortune 500 client portfolio. You will investigate alerts, validate context, and escalate incidents with full context and clear documentation.

Ideal candidates have 2+ years of hands-on SOC experience, strong SIEM/EDR/SOAR skills, and proficiency in MITRE ATT&CK. This 24/7 shift-based, office-based role in Warsaw requires independent work and excellent English

Qualifications

  • 2+ years hands-on SOC experience (L1/L2).
  • Experience with SIEM (Splunk preferred), EDR (CrowdStrike preferred), SOAR.
  • Ability to read raw events and correlate across platforms.
  • Working knowledge of MITRE ATT&CK framework and its application.
  • Clear written English communications (B2+).

Responsibilities

  • Own end-to-end investigation of alerts — from triage to closure or escalation.
  • Investigate at Tier 1–2 level using SIEM, SOAR, EDR, identity and SaaS telemetry.
  • Validate alert context, enrich indicators, build timelines, and classify activity.
  • Document investigations with evidence, reasoning, impact, and MITRE mapping.
  • Escalate confirmed or high-risk incidents with context for rapid response.
  • Maintain disciplined shift handoffs and clear action trackers.
  • Handle security requests (suspicious emails, anomalous accounts) with rigor.
  • Identify false positives and provide tuning feedback with log evidence.
  • Operate within client toolstack, data boundaries, and escalation procedures.

Skills

SOC experience
SIEM
EDR
SOAR
MITRE ATT&CK
English communication
Shift-based
Independent worker

Tools

Splunk
Coralogix
CrowdStrike Falcon
Blink Mate
Okta

Job description

SOC Analyst (L1/L2)

UnderDefense is looking for a sharp, detail-oriented SOC Analyst to join a dedicated security operations team based in Warsaw. This is a hands‑on, shift‑based role embedded in a high‑stakes environment – you will be the frontline of defense for a fast‑growing global SaaS company with 20+ offices worldwide and Fortune 500 clients.

You will operate as part of a structured UnderDefense SOC team, working directly within the client’s security ecosystem. Alerts come to you pre-filtered by a SOAR automation layer — your job is to investigate what matters, make the call, and elevate confirmed threats to the client’s incident response team with full context and zero noise.

This role is ideal for someone who wants to go deep on real‑world investigations across a modern, complex tool stack — identity, EDR, cloud, SaaS, and DevOps — all in one environment.

What you will do:

  • Own end-to-end investigation of assigned alerts — from initial triage through closure or escalation.
  • Investigate at Tier 1–2 level using SIEM (Splunk/Coralogix), SOAR (Blink Mate), EDR (CrowdStrike Falcon), identity, and SaaS telemetry.
  • Validate alert context, enrich indicators, build timelines, and determine whether activity is benign, suspicious, or confirmed malicious.
  • Document every investigation with clear evidence, reasoning, impact assessment, and MITRE ATT&CK mapping.
  • Escalate confirmed or high‑risk incidents through the agreed T3 process with sufficient technical context for rapid response.
  • Maintain disciplined shift handoffs — open investigations, active risks, and pending actions must be clear to the next analyst.
  • Handle employee-initiated security requests (suspicious emails, anomalous account behavior, lost/stolen devices) with the same rigor as platform‑generated alerts.
  • Identify false positives, automation gaps, and detection quality issues; provide structured tuning feedback with supporting log evidence.
  • Operate strictly within the agreed client toolstack, data boundaries, and escalation procedures.

Data sources you will work across:

  • Identity & SSO: Okta, Google Workspace, Microsoft (O365 + Azure AD), LastPass, Teleport, Apono
  • EDR: CrowdStrike Falcon
  • Email & Web: Perception Point, Talon, Prisma Access, Cloudflare, Palo Alto Panorama, Cisco Meraki
  • SaaS & Collaboration: Salesforce, Slack, Box, DropBox, SharePoint, Google Workspace
  • Cloud & DevOps: Wiz, GitHub, Astrix (NHI), Sweet Security, Workato, Koi
  • Data & DLP: DoControl, Reco, Monte Carlo, Coralogix
  • Threat Intel & Other: Mitiga, Sphera, internal TI feeds, correlation rules, UBA

What we are looking for:

  • 2+ years of hands‑on SOC experience (L1/L2 level)
  • Solid experience with SIEM (Splunk preferred), EDR (CrowdStrike preferred), SOAR tools
  • Ability to read raw events and correlate across multiple platforms simultaneously
  • Working knowledge of MITRE ATT&CK framework — not just the name, but the application
  • Clear, structured written communication in English — your investigation notes are read by the client’s security team (B2+ required)
  • Comfortable working in a shift‑based schedule (24/7 coverage model); day shifts are office‑based in Warsaw
  • Able to work independently, maintain documentation discipline, and hand off cleanly
  • Location: Warsaw, Poland (or willing to relocate — relocation support available)
  • Background check required (criminal record clearance)

Nice to have:

  • Certifications: CEH, GCIH, CompTIA Security+, or similar
  • Experience with identity platforms (Okta, Azure AD) and cloud security tools (Wiz, Prisma)
  • Familiarity with SOAR playbooks and automation logic

Salary:

We don’t believe in one‑size‑fits‑all. Tell us what you’re worth and let’s talk. Compensation is competitive, tied to experience level, and based on Polish employment (B2B or UoP).

About this position

Location

Warsaw (Poland)

Employment type

Full time

Department

Services

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst L1/L2 - Frontline Security Investigator
SOC Analyst L1/L2 - Frontline Security Investigator

UnderDefense LLC • Warszawa

On-site
PLN 120,000 - 180,000
Junior SOC Security Engineer
Junior SOC Security Engineer

your Jared • Warszawa

Hybrid
PLN 123,000 - 156,000
Fully remote work
Flexible contracting: B2B or Contract
SOC Analyst (Shift Lead) (f/m/d)
SOC Analyst (Shift Lead) (f/m/d)

Danaher • Kraków

On-site
PLN 140,000 - 180,000
Cybersecurity Operations Analyst
Cybersecurity Operations Analyst

Aon plc • Kraków

Hybrid
PLN 180,000 - 240,000
Cybersecurity Operations Analyst
Cybersecurity Operations Analyst

Aon Corporation • Kraków

On-site
PLN 120,000 - 180,000
Junior Cybersecurity Analyst
Junior Cybersecurity Analyst

SoftwareONE Deutschland GmbH • Warszawa

Hybrid
PLN 60,000 - 90,000
Mentoring and coaching
Learning and development opportunities
Flexible work arrangements
+1
Lead Security Operations Engineer
Lead Security Operations Engineer

Talanto • Wrocław

Hybrid
PLN 279,000 - 318,000
Private medical care
Multisport Card
Flexible remote work options
+1
Team Lead - Principal Security Detection & Response Analyst Team Lead
Team Lead - Principal Security Detection & Response Analyst Team Lead

LevelBlue, LLC. • Poland

Hybrid
PLN 180,000 - 260,000
Contract of employment
Sport card/ co-financing of vacation
Life insurance
+5
Information Security Analyst Level 1 IRC301940
Information Security Analyst Level 1 IRC301940

GlobalLogic • Kraków

Hybrid
PLN 60,000 - 80,000
Relocation support
Rotation program
Flexible opportunities
SOC Analyst Security Operations Centre Analyst Confirmed NDC
SOC Analyst Security Operations Centre Analyst Confirmed NDC

Vector Synergy • Poznań

On-site
Health insurance
Professional development opportunities
Flexible work arrangements