Security Analyst

Tenarai Europe

Town of Poland (NY)

Hybrid

USD 32,000 - 51,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Remote/Hybrid work
Office spaces
Parking
Referral bonus
Life Insurance
Development budget
Learning Platform access
MyBenefit access
Team building
Charity initiatives
Diversity & inclusion

Job summary

Tenarai Europe is seeking an experienced Level 2 Security Operations Center (SOC) Analyst to join our security team. You will act as the primary escalation point for complex security incidents, conducting deep-dive investigations across on-prem and cloud telemetry to determine scope and containment strategies.

You'll work with Microsoft Sentinel, Defender XDR, SentinelOne and Azure security services, crafting KQL queries and playbooks to detect and mitigate threats while mentoring junior

Qualifications

  • Minimum 2–4 years of enterprise or MSSP SOC experience.
  • Strong proficiency with Microsoft Sentinel and Defender XDR.
  • Advanced proficiency in KQL for data parsing, log analysis, and threat hunting.
  • Hands-on experience with SentinelOne and Defender for Endpoint.
  • Familiarity with mapping attacker behaviors to the MITRE ATT&CK framework.
  • Scripting skills in PowerShell, Python, or Bash.
  • Solid networking foundations including TCP/IP and security perimeters.

Responsibilities

  • Advanced incident investigation and validation of high-priority alerts.
  • Endpoint detection and live response forensics to identify root causes.
  • Threat containment using SentinelOne, Defender for Endpoint, and Azure AD sessions.
  • Detection engineering: develop and tune Sentinel analytics rules and KQL queries.
  • SOAR automation: build and modify response playbooks in Sentinel to improve MTTR.
  • Mentorship and guidance to Level 1 analysts.

Skills

KQL
PowerShell
Python
Bash
SentinelOne
Defender for Endpoint
Azure security
MITRE ATT&CK
TCP/IP
Cross-domain telemetry

Education

Bachelor’s Degree in Cybersecurity/CS
SC-200
AZ-500
SentinelOne Certified Professional
SentinelOne Certified Incident Responder
GCIH
GCFA
CySA+

Tools

Microsoft Sentinel
Microsoft Defender XDR
SentinelOne
Azure
Azure AD
Microsoft 365

Job description

For our clients we are seeking an experienced and analytical Level 2 (L2) Security Operations Center (SOC) Analyst to join their team. In this role, you will act as the primary escalation point for complex security anomalies. You will be responsible for conducting deep-dive incident investigations, correlating cross-domain telemetry, and driving containment strategies.

The security architecture deeply relies on Microsoft Sentinel and Microsoft Defender XDR as their cloud-native SIEM and SentinelOne as well as Microsoft Defender for Endpoint as our enterprise Endpoint Detection and Response (EDR) platform. The ideal candidate possesses a strong command of Kusto Query Language (KQL), extensive experience pivoting between endpoint forensics and cloud

infrastructure logs, and a proven track record of neutralizing threats, and have deep understanding of Microsoft Azure PaaS and SaaS security technologies.

Responsibilities:

  • Advanced Incident Investigation: Analyze and validate high-priority alerts escalated by L1 analysts. Utilize Microsoft Sentinel and Defender XDR to correlate cross-platform data sources (Azure AD, Microsoft 365, network firewalls, On-prem AD, SaaS services and multi-cloud logs) to determine the true scope and impact of an incident
  • Endpoint Detection & Response: Deep-dive into malicious host behaviors using SentinelOne and Microsoft Defender for Endpoint . Review process lifecycles, cross-examine Deep Visibility queries, analyze behavioral anomalies, and perform live response forensics to identify root causes.
  • Threat Containment & Mitigation: Execute containment playbooks to neutralize threats. This includes isolating compromised endpoints directly through SentinelOne and Microsoft Defender for Endpoint, revoking compromised cloud sessions via Azure AD, and blocking malicious Indicators of Compromise (IOCs) across security perimeters.
  • Detection Engineering & Tuning: Author, refine, and optimize Microsoft Sentinel Analytics Rules and threat hunting queries using Kusto Query Language (KQL) to minimize false positives and capture emerging threat techniques. [1, 2]
  • SOAR Automation: Build and modify automated response logic apps and playbooks within Microsoft Sentinel to improve the SOC's Mean Time to Respond (MTTR)
  • Collaboration & Mentorship: Provide technical guidance, escalation support, and constructive feedback to Level 1 analysts to uplift overall team competency

Job requirements:

  • Experience: Minimum of 2–4 years of dedicated experience working inside an enterprise or MSSP Security Operations Center, with specific emphasis on tier-2 incident response.
  • SIEM Mastery: Highly proficient with Microsoft Sentinel, Microsoft Defender XDR and other Microsoft Defender suit including a strong operational grasp of log architecture, data connectors, and workbook creation.
  • Query Language: Advanced proficiency in KQL (Kusto Query Language) for data parsing, log analysis, and active threat hunting.
  • EDR Mastery: Hands-on experience navigating SentinelOne (Singularity) and Defender for Endpoint, utilizing features like Ranger, Deep Visibility, and its automated remediation/rollback capabilities.
  • Framework Alignment: Practical familiarity mapping real-world attacker behaviors to the MITRE ATT&CK framework to guide active investigations.
  • Scripting: Proficiency with PowerShell or Python or Bash to parse complex logs, interface with APIs, and automate routine tasks.
  • Networking: Strong basic networking foundational knowledge including but not limited to TCP/IP stack, packet capturing and NextGen Firewalling.

Preferred Certifications & Education

  • Bachelor’s Degree in Cybersecurity, Computer Science, or a related technical discipline (or equivalent practical experience).
  • Microsoft Certifications: Microsoft Certified: Security Operations Analyst Associate (SC-200) or Microsoft Certified: Azure Security Engineer Associate (AZ-500).
  • SentinelOne Certifications: SentinelOne Certified Professional or SentinelOne Certified Incident Responder.
  • General Security Certifications: GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), or CompTIA Cybersecurity Analyst (CySA+).

Must possess a legal work permit in Poland

General benefits - depends on the form of employment

  • Remote work or Hybrid work model
  • Attractively located office with collaboration spaces
  • Onsite parking space for employees
  • Referral program with financial bonus
  • Life Insurance
  • Budget for development (including language courses and others), clear career path with the possibility to gain experience in international environment
  • Access to internal Learning Platform with multiple trainings oriented for professional growth
  • Access to MyBenefit platform (Multisport included)
  • Team Building activities
  • Charity initiatives
  • Working environment promoting diversity and inclusion
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Analyst (SentinelOne)
Senior SOC Analyst (SentinelOne)

Experis ManpowerGroup Sp. z o.o. • Colorado

On-site
Medicover healthcare package
Multisport card
Access to an e-learning platform
+1
Security Operations Analyst
Security Operations Analyst

Jobgether • United States

Remote
USD 70,000 - 100,000
Remote-first
Unlimited PTO
Medical, dental, vision
+4
Senior Security Analyst
Senior Security Analyst

Katalyst • North Carolina

On-site
USD 120,000 - 180,000
401(k) matching
Paid time off
Health insurance
+1
Information Security Analyst
Information Security Analyst

NPAworldwide • City of Syracuse (NY)

On-site
USD 85,000 - 90,000
Incident Response Analyst - L2
Incident Response Analyst - L2

SOFTSWISS • Georgia

On-site
USD 75,000 - 120,000
Private health insurance
Sports benefits
Mental Health Program
+7
Security Operations Analyst
Security Operations Analyst

MultiPlan • McLean (VA)

On-site
USD 95,000 - 105,000
Health insurance
401k plan
Bonus opportunity
Staff Windows Low Level C++ Engineer - Endpoint security
Staff Windows Low Level C++ Engineer - Endpoint security

SentinelOne • Town of Italy (NY)

Remote
USD 100,000 - 150,000
Flexible working hours
Generous employee stock plan
Yearly bonus
+1
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Security Analyst – Endpoint Security & Infrastructure
Security Analyst – Endpoint Security & Infrastructure

Interscripts, Inc. • Daly City (CA)

On-site
USD 90,000 - 120,000