368,941open jobs
9,452companies
47,951added this week
Browse all
Location
Remote/Hybrid (Poland)
Seniority
Junior · 2+ years exp
Overview
Company
Impact
Profile match
Tenarai (formerly Infogain) is a Silicon Valley-based global technology services firm that specializes in enterprise artificial intelligence acceleration, digital transformation, and software engineering. The company partners with Fortune 500 leaders across sectors such as technology, retail, healthcare, and travel to design and implement custom AI-driven solutions and modernize data architectures.

Project info:

For our clients we are seeking an experienced and analytical Level 2 (L2) Security Operations Center (SOC) Analyst to join their team. In this role, you will act as the primary escalation point for complex security anomalies. You will be responsible for conducting deep-dive incident investigations, correlating cross-domain telemetry, and driving containment strategies.

The security architecture deeply relies on Microsoft Sentinel and Microsoft Defender XDR as their cloud-native SIEM and SentinelOne as well as Microsoft Defender for Endpoint as our enterprise Endpoint Detection and Response (EDR) platform. The ideal candidate possesses a strong command of Kusto Query Language (KQL), extensive experience pivoting between endpoint forensics and cloud

infrastructure logs, and a proven track record of neutralizing threats, and have deep understanding of Microsoft Azure PaaS and SaaS security technologies.

Responsibilities:

  • Advanced Incident Investigation: Analyze and validate high-priority alerts escalated by L1 analysts. Utilize Microsoft Sentinel and Defender XDR to correlate cross-platform data sources (Azure AD, Microsoft 365, network firewalls, On-prem AD, SaaS services and multi-cloud logs) to determine the true scope and impact of an incident
  • Endpoint Detection & Response: Deep-dive into malicious host behaviors using SentinelOne and Microsoft Defender for Endpoint . Review process lifecycles, cross-examine Deep Visibility queries, analyze behavioral anomalies, and perform live response forensics to identify root causes.
  • Threat Containment & Mitigation: Execute containment playbooks to neutralize threats. This includes isolating compromised endpoints directly through SentinelOne and Microsoft Defender for Endpoint, revoking compromised cloud sessions via Azure AD, and blocking malicious Indicators of Compromise (IOCs) across security perimeters.
  • Detection Engineering & Tuning: Author, refine, and optimize Microsoft Sentinel Analytics Rules and threat hunting queries using Kusto Query Language (KQL) to minimize false positives and capture emerging threat techniques. [1, 2]
  • SOAR Automation: Build and modify automated response logic apps and playbooks within Microsoft Sentinel to improve the SOC's Mean Time to Respond (MTTR)
  • Collaboration & Mentorship: Provide technical guidance, escalation support, and constructive feedback to Level 1 analysts to uplift overall team competency

Job requirements:

  • Experience: Minimum of 2-4 years of dedicated experience working inside an enterprise or MSSP Security Operations Center, with specific emphasis on tier-2 incident response.
  • SIEM Mastery: Highly proficient with Microsoft Sentinel, Microsoft Defender XDR and other Microsoft Defender suit including a strong operational grasp of log architecture, data connectors, and workbook creation.
  • Query Language: Advanced proficiency in KQL (Kusto Query Language) for data parsing, log analysis, and active threat hunting.
  • EDR Mastery: Hands-on experience navigating SentinelOne (Singularity) and Defender for Endpoint, utilizing features like Ranger, Deep Visibility, and its automated remediation/rollback capabilities.
  • Framework Alignment: Practical familiarity mapping real-world attacker behaviors to the MITRE ATT&CK framework to guide active investigations.
  • Scripting: Proficiency with PowerShell or Python or Bash to parse complex logs, interface with APIs, and automate routine tasks.
  • Networking: Strong basic networking foundational knowledge including but not limited to TCP/IP stack, packet capturing and NextGen Firewalling.

Preferred Certifications & Education

  • Bachelor’s Degree in Cybersecurity, Computer Science, or a related technical discipline (or equivalent practical experience).
  • Microsoft Certifications: Microsoft Certified: Security Operations Analyst Associate (SC-200) or Microsoft Certified: Azure Security Engineer Associate (AZ-500).
  • SentinelOne Certifications: SentinelOne Certified Professional or SentinelOne Certified Incident Responder.
  • General Security Certifications: GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), or CompTIA Cybersecurity Analyst (CySA+).

Must possess a legal work permit in Poland

Benefits:

General benefits - depends on the form of employment

  • Remote work or Hybrid work model
  • Attractively located office with collaboration spaces
  • Onsite parking space for employees
  • Referral program with financial bonus
  • Life Insurance
  • Budget for development (including language courses and others), clear career path with the possibility to gain experience in international environment
  • Access to internal Learning Platform with multiple trainings oriented for professional growth

Lifestyle benefits:

  • Access to MyBenefit platform (Multisport included)
  • Team Building activities
  • Charity initiatives
  • Working environment promoting diversity and inclusion

Health benefits:

  • Private medical care - Platinum Package
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,941 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$51k – $111k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Cork
Bash
Node JS
PowerShell
Python
JavaScript
AI/ML
AI Agents
DevOps
Rest API
Windows Server
Marketing
Salesforce
Apply
$111k – $150k per year • In office • Full-Time • 3+ years exp • United States
PowerShell
DevOps
Windows Server
Apply
$22k – $62k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Hyderabad
C#
Python
TypeScript
AI/ML
A2A
AI Agents
Copilot
Function Calling
Google AI Studio
Model Context Protocol
OpenAI
RAG
Semantic Search
Semantic Search
DevOps
Azure
Rest API
Analytics
Power BI
Management
Power Apps
Power Automate
Apply
$42k – $86k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Genoa • Turin
Java
Java
Spring Boot
Databases
Apache Kafka
InfluxDB
PostgreSQL
DevOps
Azure
CI/CD
Docker
Grafana
Kubernetes
Apply
Data Analyst 1 day ago
$38k per year (gross) • Remote/Hybrid • Full-Time • Bachelor's Degree • Bucharest
Python
SQL
AI/ML
Hadoop
DevOps
Azure
Analytics
Power BI
Apply
$50k – $81k per year (Estimated) • Remote/Hybrid • Kraków
Groovy
Java
TypeScript
Java
Maven
Spring Boot
DevOps
CI/CD
Docker
GCP
Git
Jenkins
QA
JMeter
Apply
Senior Java Developer 12 days ago
Remote/Hybrid • 6+ years exp
Java
Python
TypeScript
Java
Spring Boot
DevOps
CI/CD
Docker
GCP
GitHub Actions
gRPC
Jenkins
Kubernetes
Prometheus
Rest API
GitHub
Apply
Senior Java Developer 13 days ago
$62k – $99k per year (Estimated) • Remote/Hybrid • 4+ years exp • Kraków
Java
Kotlin
Java
Maven
DevOps
CI/CD
Docker
GCP
Git
Grafana
Jenkins
Kubernetes
Prometheus
Apply
$84k – $192k per year (Estimated) • Remote • 5+ years exp • Bachelor's Degree
DevOps
AWS
Azure
GCP
Cybersecurity
Microsoft Defender
Trend Micro
Apply
$86k – $108k per year • Remote/Hybrid • Full-Time • 7+ years exp • Kraków
Node JS
Python
JavaScript
AI/ML
Claude
Copilot
Cursor
Function Calling
LLM
RAG
AI Agents
Anthropic
Devin
LLM Evaluation
Frontend
GraphQL
DevOps
AWS
Azure
CI/CD
Docker
GCP
GitHub
Apply
See all jobs
This is one of many
368,941 more open roles from verified company boards, updated every day.