Unlock Full Resume Report

New offer - be the first one to apply!

September 16, 2026

Senior SOC Analyst

Senior • Remote

395,200 - 478,400 PLN/yr

Warsaw, Maz, Poland

Quick Facts

  • Role: Senior SOC Analyst
  • Work mode: Fully remote with occasional business travel to London
  • Contract: B2B
  • Availability: On-call support outside standard hours and weekends

Description

You will operate the SOC by monitoring and triaging security alerts from SIEM, EDR, NDR, and cloud sources, escalating to the SOC Lead when needed. The role covers end-to-end incident handling (analysis, containment, remediation coordination, restoration, and post-incident documentation), plus vulnerability management, purple teaming, and hypothesis-driven threat hunting. You will also build and improve detections using MITRE ATT&CK, playbooks/runbooks, correlation queries, and scripted automation.

Responsibilities

  • Monitor security alerts and conduct triage and investigation of incidents
  • Lead/support complex incident response: containment, threat removal, recovery, and incident documentation
  • Create and maintain incident response playbooks/runbooks; identify gaps and recommend improvements
  • Perform root cause analysis and participate in post-incident reviews
  • Write clear incident reports for technical and business stakeholders
  • Support on-call duties for high-priority incidents
  • Perform vulnerability scanning and assessments using Tenable, Qualys, or Rapid7 (planned and ad hoc)
  • Prioritize vulnerabilities using CVSS, threat intel, and asset criticality; track remediation progress and escalate delays
  • Track new CVEs and exploit trends; advise risk-based prioritization
  • Co-create vulnerability reporting (trends, patch compliance, risk reduction metrics)
  • Participate in purple teaming with red team inputs
  • Map adversary techniques to MITRE ATT&CK and use results to find detection gaps
  • Tune SIEM detection rules, correlation queries, and alerts based on TTPs
  • Conduct MITRE-aligned hypothesis-driven threat hunting and monitor threat group activity/TTPs
  • Analyze logs from endpoints, firewall/proxy, cloud, and identity systems
  • Enhance investigations with threat intelligence and IOC correlation across data sources
  • Collaborate with IT/engineering to reduce false positives and improve signal quality
  • Maintain SOC documentation (runbooks, knowledge base articles, escalation procedures)
  • Support compliance evidence and audits (e.g., SOC 2, ISO 27001, NIST CSF)
  • Mentor junior analysts (knowledge sharing and hands-on support)

Requirements

  • Minimum 5 years of hands-on SOC operations or incident response experience
  • Ability to independently lead investigations and coordinate high-severity incident response when SOC Lead is not available
  • Ability to analyze complex incidents and clearly communicate investigation methodology, evidence, containment decisions, and next steps
  • Very strong SIEM knowledge (Splunk, Microsoft Sentinel, or Sumo Logic)
  • Hands-on EDR experience (CrowdStrike Falcon or Microsoft Defender)
  • Documented triage experience and ability to respond to high volumes of alerts and incidents
  • Practical vulnerability management experience (scanning, prioritization, remediation tracking)
  • Good networking knowledge: TCP/IP, DNS, HTTP/HTTPS, firewalls, proxy basics
  • Experience analyzing endpoint, network, cloud, and SaaS logs
  • Knowledge of MITRE ATT&CK for analysis and detection development
  • Scripting experience for analysis/automation (Python, PowerShell, or Bash)
  • Strong analytical and problem-solving skills with high attention to detail
  • Excellent communication skills in English (C1)

Benefits

  • Fully remote role with occasional London travel
  • B2B contract
  • Onboarding in London for several days

Similar jobs you might like