Relomote
Remote JobsRelocation Jobs
Add companySaved
Relomote

Relomote is a job board for remote, hybrid, and relocation jobs — every listing AI-classified for the countries it actually hires from, or the visa and relocation support it offers.

LinkedInCrunchbase

Remote jobs by category

  • Remote Engineering & Development jobs
  • Remote Customer Support jobs
  • Remote Design jobs
  • Remote Marketing jobs
  • Remote Sales jobs
  • Remote Product jobs
  • Remote Data & Analytics jobs
  • Remote People & Talent jobs
  • Remote Writing & Content Creation jobs
  • Remote Finance jobs
  • Remote Legal & Compliance jobs
  • Remote Operations & Admin jobs
  • Remote Data Entry jobs
  • Remote Virtual Assistant jobs
  • Remote Education/Training jobs
  • Remote Healthcare/Clinical jobs
  • Remote Other jobs

Remote jobs by location

  • Work from anywhere jobs
  • Remote jobs in Africa
  • Remote jobs in Asia
  • Remote jobs in Europe
  • Remote jobs in Latin America
  • Remote jobs in Middle East
  • Remote jobs in North America
  • Remote jobs in Oceania
  • All remote jobs →

Relocation & visa sponsorship

  • Visa sponsorship jobs
  • Relocation package jobs
  • Relocate to Europe
  • Relocate to Germany
  • Relocate to Netherlands
  • Relocate to Spain
  • Relocate to Portugal
  • Relocate to Greece
  • Relocate to United Kingdom
  • Relocate to Canada
  • Relocate to Australia
  • Relocate to Sweden
  • Relocate to Switzerland
  • Relocate to Japan
  • Relocate to United Arab Emirates
  • All relocation jobs →

© 2026 RelomoteAboutPrivacyTerms

Contact [email protected] · Built by Mahmoud

Relomote
Remote JobsRelocation Jobs
Add companySaved
TE

Security Analyst

Tenarai Europe
Posted 12 hours ago
🇵🇱Poland🏢Hybrid📁Engineering & Development
Is this job info correct?

Project info:


For our clients we are seeking an experienced and analytical Level 2 (L2) Security Operations Center (SOC) Analyst to join their team. In this role, you will act as the primary escalation point for complex security anomalies. You will be responsible for conducting deep-dive incident investigations, correlating cross-domain telemetry, and driving containment strategies.

The security architecture deeply relies on Microsoft Sentinel and Microsoft Defender XDR as their cloud-native SIEM and SentinelOne as well as Microsoft Defender for Endpoint as our enterprise Endpoint Detection and Response (EDR) platform. The ideal candidate possesses a strong command of Kusto Query Language (KQL), extensive experience pivoting between endpoint forensics and cloud

infrastructure logs, and a proven track record of neutralizing threats, and have deep understanding of Microsoft Azure PaaS and SaaS security technologies.



Responsibilities:


  • Advanced Incident Investigation: Analyze and validate high-priority alerts escalated by L1 analysts. Utilize Microsoft Sentinel and Defender XDR to correlate cross-platform data sources (Azure AD, Microsoft 365, network firewalls, On-prem AD, SaaS services and multi-cloud logs) to determine the true scope and impact of an incident
  • Endpoint Detection & Response: Deep-dive into malicious host behaviors using SentinelOne and Microsoft Defender for Endpoint . Review process lifecycles, cross-examine Deep Visibility queries, analyze behavioral anomalies, and perform live response forensics to identify root causes.
  • Threat Containment & Mitigation: Execute containment playbooks to neutralize threats. This includes isolating compromised endpoints directly through SentinelOne and Microsoft Defender for Endpoint, revoking compromised cloud sessions via Azure AD, and blocking malicious Indicators of Compromise (IOCs) across security perimeters.
  • Detection Engineering & Tuning: Author, refine, and optimize Microsoft Sentinel Analytics Rules and threat hunting queries using Kusto Query Language (KQL) to minimize false positives and capture emerging threat techniques. [1, 2]
  • SOAR Automation: Build and modify automated response logic apps and playbooks within Microsoft Sentinel to improve the SOC's Mean Time to Respond (MTTR)
  • Collaboration & Mentorship: Provide technical guidance, escalation support, and constructive feedback to Level 1 analysts to uplift overall team competency


Job requirements:


  • Experience: Minimum of 2–4 years of dedicated experience working inside an enterprise or MSSP Security Operations Center, with specific emphasis on tier-2 incident response.
  • SIEM Mastery: Highly proficient with Microsoft Sentinel, Microsoft Defender XDR and other Microsoft Defender suit including a strong operational grasp of log architecture, data connectors, and workbook creation.
  • Query Language: Advanced proficiency in KQL (Kusto Query Language) for data parsing, log analysis, and active threat hunting.
  • EDR Mastery: Hands-on experience navigating SentinelOne (Singularity) and Defender for Endpoint, utilizing features like Ranger, Deep Visibility, and its automated remediation/rollback capabilities.
  • Framework Alignment: Practical familiarity mapping real-world attacker behaviors to the MITRE ATT&CK framework to guide active investigations.
  • Scripting: Proficiency with PowerShell or Python or Bash to parse complex logs, interface with APIs, and automate routine tasks.
  • Networking: Strong basic networking foundational knowledge including but not limited to TCP/IP stack, packet capturing and NextGen Firewalling.


Preferred Certifications & Education

  • Bachelor’s Degree in Cybersecurity, Computer Science, or a related technical discipline (or equivalent practical experience).
  • Microsoft Certifications: Microsoft Certified: Security Operations Analyst Associate (SC-200) or Microsoft Certified: Azure Security Engineer Associate (AZ-500).
  • SentinelOne Certifications: SentinelOne Certified Professional or SentinelOne Certified Incident Responder.
  • General Security Certifications: GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), or CompTIA Cybersecurity Analyst (CySA+).


Must possess a legal work permit in Poland


Benefits:


General benefits - depends on the form of employment


  • Remote work or Hybrid work model
  • Attractively located office with collaboration spaces
  • Onsite parking space for employees
  • Referral program with financial bonus
  • Life Insurance
  • Budget for development (including language courses and others), clear career path with the possibility to gain experience in international environment
  • Access to internal Learning Platform with multiple trainings oriented for professional growth


Lifestyle benefits:


  • Access to MyBenefit platform (Multisport included)
  • Team Building activities
  • Charity initiatives
  • Working environment promoting diversity and inclusion


Health benefits:


  • Private medical care - Platinum Package

Similar jobs

Similar jobs

Onwelo logo

SOC Tier 2 Analyst (Cybersecurity)

Onwelo

🇵🇱PolandYesterday
Pmicareers logo

Senior IT Security Analyst - Data & AI Platform

Pmicareers

🇵🇱Poland2 days ago
ARHS logo

Cybersecurity Vulnerability Analyst

ARHS

🇵🇱Poland1 weeks ago
NO

Senior GRC Analyst & Information Security Officer

Northlandpower

🇵🇱Poland1 weeks ago
Nttdata Solutions logo

IT Security Analyst

Nttdata Solutions

🇵🇱Poland2 weeks ago
SolarWinds logo

Senior Security Operations (SOC) Engineer/Analyst

SolarWinds

🌍Czech Republic, Poland3 weeks ago