SOC Analyst
- Moves you to
- Poland
- Support
- Relocation support
- Posted
- Sep 27, 2026
SOC Analyst
UnderDefense is looking for a sharp, detail-oriented SOC Analyst to join a dedicated security operations team based in Warsaw. This is a hands-on, shift-based role embedded in a high-stakes environment - you will be the frontline of defense for a fast-growing global SaaS company with 20+ offices worldwide and Fortune 500 clients.
You will operate as part of a structured UnderDefense SOC team, working directly within the client's security ecosystem. Alerts come to you pre-filtered by a SOAR automation layer — your job is to investigate what matters, make the call, and escalate confirmed threats to the client's incident response team with full context and zero noise.
This role is ideal for someone who wants to go deep on real-world investigations across a modern, complex tool stack — identity, EDR, cloud, SaaS, and DevOps — all in one environment.
What you will do
Own end-to-end investigation of assigned alerts — from initial triage through closure or escalation.
Investigate at Tier 1–2 level using SIEM (Splunk/Coralogix), SOAR (Blink Mate), EDR (CrowdStrike Falcon), identity, and SaaS telemetry.
Validate alert context, enrich indicators, build timelines, and determine whether activity is benign, suspicious, or confirmed malicious.
Document every investigation with clear evidence, reasoning, impact assessment, and MITRE ATT&CK mapping.
Escalate confirmed or high-risk incidents through the agreed T3 process with sufficient technical context for rapid response.
Maintain disciplined shift handoffs — open investigations, active risks, and pending actions must be clear to the next analyst.
Handle employee-initiated security requests (suspicious emails, anomalous account behavior, lost/stolen devices) with the same rigor as platform-generated alerts.
Identify false positives, automation gaps, and detection quality issues; provide structured tuning feedback with supporting log evidence.
Operate strictly within the agreed client toolstack, data boundaries, and escalation procedures.
Data sources you will work across
Identity & SSO: Okta, Google Workspace, Microsoft (O365 + Azure AD), LastPass, Teleport, Apono
EDR: CrowdStrike Falcon
Email & Web: Perception Point, Talon, Prisma Access, Cloudflare, Palo Alto Panorama, Cisco Meraki
SaaS & Collaboration: Salesforce, Slack, Box, DropBox, SharePoint, Google Workspace
Cloud & DevOps: Wiz, GitHub, Astrix (NHI), Sweet Security, Workato, Koi
Data & DLP: DoControl, Reco, Monte Carlo, Coralogix
Threat Intel & Other: Mitiga, Sphera, internal TI feeds, correlation rules, UBA
What we are looking for
2+ years of hands-on SOC experience (L1/L2 level)
Solid experience with SIEM (Splunk preferred), EDR (CrowdStrike preferred), SOAR tools
Ability to read raw events and correlate across multiple platforms simultaneously
Working knowledge of MITRE ATT&CK framework — not just the name, but the application
Clear, structured written communication in English — your investigation notes are read by the client's security team (B2+ required)
Comfortable working in a shift-based schedule (24/7 coverage model); day shifts are office-based in Warsaw
Able to work independently, maintain documentation discipline, and hand off cleanly
Location: Warsaw, Poland (or willing to relocate — relocation support available)
Background check required (criminal record clearance)
Nice to have:
Experience with identity platforms (Okta, Azure AD) and cloud security tools (Wiz, Prisma)
Familiarity with SOAR playbooks and automation logic
Certifications: CEH, GCIH, CompTIA Security+, or similar
Salary
We don't believe in one-size-fits-all. Tell us what you're worth and let's talk. Compensation is competitive, tied to experience level, and based on Polish employment (B2B or UoP).
Interested? Send your CV to recruiter@underdefense.com