Security Operations Analyst (L1)

Europe

We are inviting you, a highly motivated and results-oriented Security Operations Analyst to join our team on a full-time basis.

Our team has unique expertise in research, analysis, and product development. By relying on technical insights and a data-driven approach, we create disruptive future-defining innovations of the fin-tech industry that remain our basis for success.

Responsibilities

  • Monitor prioritized alert queues and validate whether alerts indicate real risk
  • Enrich cases and correlate relevant endpoint, identity, authentication, network, service, asset, user, timeline, and business context
  • Perform initial investigations, classify alerts, assess preliminary severity and scope, and document the evidence and reasoning in the case-management system
  • Close false positives and execute approved low-risk actions only through defined runbooks
  • Escalate suspected incidents, privileged-account issues, and high-impact or production-impact cases to L2, the manager, or Incident Response
  • Maintain clear handover notes and support improvements to case quality and runbooks

Requirements

  • Hands-on experience with security alert triage through work, an internship, or a practical lab, including use of at least one SIEM and exposure to EDR or XDR and case-management workflows
  • Ability to build basic searches or queries, filter security events, and correlate related activity across more than one data source (Experience with basic SIEM query languages such as KQL, EQL)
  • Ability to interpret common endpoint, identity, authentication, network, DNS, HTTP, and service or cloud audit telemetry at an initial-investigation level
  • Working fundamentals of Windows and Linux, TCP/IP, DNS, HTTP, authentication, access control, and common attack patterns such as phishing, credential abuse, malware execution, and suspicious account activity
  • Ability to distinguish true positives, false positives, and benign activity; assign a preliminary severity; identify affected users or assets; and recognize when scope or impact is uncertain
  • Basic use of indicators of compromise, reputation sources, and threat-intelligence context, with awareness of the MITRE ATT&CK framework
  • Ability to create a concise investigation timeline and document evidence, actions, conclusions, and handover or escalation notes in a case-management system
  • Ability to follow approved runbooks, perform only authorized low-risk actions, recognize the limits of L1 authority, and escalate suspected incidents correctly

Will be a plus

  • Simple Python or PowerShell scripts for investigation and enrichment
  • Exposure to cloud, email-security, or SaaS audit logs and common phishing-investigation workflows
  • Practical cybersecurity labs or an entry-level certification such as Security+ or CySA+
  • Experience with MacOS

We offer

  • Tax expenses coverage for private entrepreneurs in Ukraine
  • Expert support and guidance for Ukrainian private entrepreneurs
  • 20 paid vacation days per year
  • 10 paid sick leave days per year
  • Public holidays as per the company's approved Public holiday list
  • Medical insurance
  • Opportunity to work remotely
  • Professional education budget
  • Language learning budget
  • Wellness budget (gym membership, sports gear and related expenses)

 

Create a Job Alert

Interested in building your career at JustMarkets? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf