Security Operations Analyst (L1)

3 weeks, 2 days ago
Full-time
Entry Level
Cybersecurity
JustMarkets

JustMarkets

JustMarkets is a leading online trading platform that offers a wide range of financial instruments including Forex, CFDs, Gold, and Oil. With low spreads, high leverage up to 1:3000, and fast execution, JustMarkets provides a next-level trading experie...

Capital Markets
1-10

Description

  • Monitor prioritized alert queues and determine whether alerts represent genuine risk.
  • Enrich cases by correlating endpoint, identity, authentication, network, asset, user, timeline, and business context.
  • Conduct initial investigations, classify alerts, assess preliminary severity and scope, and document evidence in the case-management system.
  • Close false positives and perform approved low-risk actions according to defined runbooks.
  • Escalate suspected incidents, privileged-account issues, and high-impact or production-impact cases appropriately.
  • Maintain clear handover notes and contribute to improving case quality and investigation runbooks.

Requirements

  • Hands-on experience with security alert triage through employment, an internship, or practical labs.
  • Experience using at least one SIEM, with exposure to EDR or XDR and case-management workflows.
  • Ability to build basic searches or queries using tools such as KQL or EQL and correlate activity across multiple data sources.
  • Ability to interpret endpoint, identity, authentication, network, DNS, HTTP, service, and cloud audit telemetry.
  • Working knowledge of Windows, Linux, TCP/IP, DNS, HTTP, authentication, access control, and common attack patterns.
  • Ability to distinguish true positives, false positives, and benign activity; assess preliminary severity; and identify affected users or assets.
  • Basic familiarity with indicators of compromise, reputation sources, threat intelligence, and MITRE ATT&CK.
  • Ability to create investigation timelines and document evidence, actions, conclusions, handovers, and escalations.
  • Ability to follow approved runbooks, perform only authorized low-risk actions, and recognize L1 escalation boundaries.
  • Preferred: Python or PowerShell scripting, cloud/email/SaaS security logs, phishing investigations, cybersecurity labs, Security+ or CySA+, and macOS experience.

Benefits

  • 20 paid vacation days annually.
  • 10 paid sick leave days annually.
  • Public holidays according to the company holiday calendar.
  • Medical budget.
  • Remote work opportunity.
  • Professional education budget.
  • Language learning budget.
  • Wellness budget covering gym memberships, sports equipment, and related expenses.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Manager, Threat Intelligence

PDI Technologies, 1K-5K Gas Utilities

PDI Technologies is seeking a Threat Intelligence, Threat Hunting, and Detection Engineering leader to build and lead a SOC program that protects more than 12,000 convenience retail, petroleum, hospitality, and automotive customers.

AWS Azure Cybersecurity Python SIEM Splunk
3 hours, 36 minutes ago

Cyber Security Specialist

RecargaPay 251-1K Capital Markets

RecargaPay is hiring a Cyber Security Specialist to join its remote CSIRT team and lead detection, response, containment, and automation for security incidents across its cloud-native payments platform.

AWS Bash CrowdStrike Cybersecurity Elasticsearch Kibana Linux Python
1 week, 2 days ago

IT SOX Admin

CareDx 251-1K Pharmaceuticals

CareDx is seeking an IT compliance and systems documentation professional to strengthen system governance, access controls, audit readiness, and operational integrity in its regulated precision-medicine diagnostics environment.

Active Directory Git NetSuite
2 weeks, 1 day ago

Senior Detection Engineering & Threat Hunting Analyst

Huntress 251-1K Professional Services

Huntress is hiring a remote US Senior Detection Engineering and Threat Hunting Analyst to develop scalable detections and proactively identify stealthy threats across millions of endpoints and identities supporting its 24/7 SOC.

Azure Cybersecurity Git Linux macOS
2 weeks, 4 days ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers