SOC Analyst L1/L2 - Frontline Security Investigator

UnderDefense LLC

Warszawa

On-site

PLN 120,000 - 180,000

Full time

7 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

UnderDefense is seeking a sharp SOC Analyst (L1/L2) based in Warsaw to join a dedicated security operations team embedded with a Fortune 500 client portfolio. You will investigate alerts, validate context, and escalate incidents with full context and clear documentation.

Ideal candidates have 2+ years of hands-on SOC experience, strong SIEM/EDR/SOAR skills, and proficiency in MITRE ATT&CK. This 24/7 shift-based, office-based role in Warsaw requires independent work and excellent English

Qualifications

  • 2+ years hands-on SOC experience (L1/L2).
  • Experience with SIEM (Splunk preferred), EDR (CrowdStrike preferred), SOAR.
  • Ability to read raw events and correlate across platforms.
  • Working knowledge of MITRE ATT&CK framework and its application.
  • Clear written English communications (B2+).

Responsibilities

  • Own end-to-end investigation of alerts — from triage to closure or escalation.
  • Investigate at Tier 1–2 level using SIEM, SOAR, EDR, identity and SaaS telemetry.
  • Validate alert context, enrich indicators, build timelines, and classify activity.
  • Document investigations with evidence, reasoning, impact, and MITRE mapping.
  • Escalate confirmed or high-risk incidents with context for rapid response.
  • Maintain disciplined shift handoffs and clear action trackers.
  • Handle security requests (suspicious emails, anomalous accounts) with rigor.
  • Identify false positives and provide tuning feedback with log evidence.
  • Operate within client toolstack, data boundaries, and escalation procedures.

Skills

SOC experience
SIEM
EDR
SOAR
MITRE ATT&CK
English communication
Shift-based
Independent worker

Tools

Splunk
Coralogix
CrowdStrike Falcon
Blink Mate
Okta

Job description

UnderDefense is seeking a sharp SOC Analyst (L1/L2) based in Warsaw to join a dedicated security operations team embedded with a Fortune 500 client portfolio. You will investigate alerts, validate context, and escalate incidents with full context and clear documentation.

Ideal candidates have 2+ years of hands-on SOC experience, strong SIEM/EDR/SOAR skills, and proficiency in MITRE ATT&CK. This 24/7 shift-based, office-based role in Warsaw requires independent work and excellent English

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst (L1/L2)
SOC Analyst (L1/L2)

UnderDefense LLC • Warszawa

On-site
PLN 120,000 - 180,000
Junior SOC Security Engineer
Junior SOC Security Engineer

your Jared • Warszawa

Hybrid
PLN 123,000 - 156,000
Fully remote work
Flexible contracting: B2B or Contract
Security Analyst (L2) — 24/7 SIEM, Threat Detection & Response
Security Analyst (L2) — 24/7 SIEM, Threat Detection & Response

HCLTech • Kraków

On-site
PLN 150,000 - 210,000
Life insurance
Private medical care
MultiSport Card
+3
SOC Analyst I: Incident Triage & Monitoring (Hybrid)
SOC Analyst I: Incident Triage & Monitoring (Hybrid)

GlobalLogic • Kraków

Hybrid
PLN 60,000 - 80,000
Relocation support
Rotation program
Flexible opportunities
Junior SOC Security Analyst - Incident Response
Junior SOC Security Analyst - Incident Response

Bunge Iberica SA • Warszawa

On-site
PLN 70,000 - 100,000
Information Security Analyst Level 1 IRC301940
Information Security Analyst Level 1 IRC301940

GlobalLogic • Kraków

Hybrid
PLN 60,000 - 80,000
Relocation support
Rotation program
Flexible opportunities
Senior Cybersecurity & SIEM Specialist | SOC & Detection
Senior Cybersecurity & SIEM Specialist | SOC & Detection

SEIDOR • Warszawa

On-site
PLN 180,000 - 260,000
SOC L1 Security Operator – On-Site Blue Team Monitor
SOC L1 Security Operator – On-Site Blue Team Monitor

DAGMA Sp. z o. o. • Katowice

On-site
PLN 90,000 - 150,000
Szkolenia IT
Zatrudnienie na pełny etat
Profesjonalny zespół
+8
SOC Analyst: Threat Detection & Incident Response Expert
SOC Analyst: Threat Detection & Incident Response Expert

Vector Synergy • Poznań

On-site
PLN 120,000 - 180,000
SOC Analyst (Shift Lead) (f/m/d)
SOC Analyst (Shift Lead) (f/m/d)

Danaher • Kraków

On-site
PLN 140,000 - 180,000