Stanislav
SOC Analyst T1
- Considering positions:
- SOC Analyst T1, Фахівець з інформаційної безпеки
- City of residence:
- Ivano-Frankivsk
- Ready to work:
- Remote
Contact information
The job seeker has entered a phone number .
Name, contacts and photo are only available to registered employers. To access the candidates' personal information, log in as an employer or sign up.
You can get this candidate's contact information from https://www.work.ua/resumes/19740076/
Work experience
L1 IT Operations Enginner
from 01.2026 to now
(8 months)
Diya, Дистанційно (IT)
Managed user accounts, mailbox permissions, shared mailboxes, distribution lists, and mail flow troubleshooting in Microsoft Exchange Online and Microsoft Entra ID.
* Administered Microsoft 365 identities, licensing, and user access.
* Troubleshot Microsoft Intune device enrollment, Autopilot provisioning, compliance status, and synchronization issues between Intune and Microsoft Entra ID.
* Investigated device compliance issues and verified remediation through Microsoft Intune and Microsoft 365 administration portals.
* Performed initial Microsoft Defender for Endpoint investigations by reviewing device timelines, alerts, process trees, file hashes, command-line activity, and alert evidence prior to escalation.
* Conducted phishing investigations by analyzing email headers, sender reputation, domains, URLs, attachments, and indicators of compromise (IOCs).
* Investigated suspicious authentication activity involving Microsoft Entra ID, Conditional Access, MFA, Outlook, Teams, and Exchange Online.
* Supported endpoint administration, software deployment, remote troubleshooting, and user onboarding/offboarding within Microsoft 365 environments.
* Collaborated with senior engineers to investigate security-related incidents and perform initial alert triage.
Knowledge and skills
- Microsoft 365
- Active Directory
- PowerShell
- DHCP
- DNS settings
- Windows Server Administration
- Maintenance of technical documentation
- Troubleshooting
Additional information
Security Projects & Hands-on Experience
Microsoft Defender for Endpoint
* Investigated endpoint alerts using device timelines, process trees, file hashes, command-line activity, authentication events, and MITRE ATT&CK mappings.
* Performed initial malware triage and documented investigation findings.
Microsoft Sentinel & Azure Arc
* Onboarded Windows endpoints to Azure Arc.
* Configured log collection through Azure Log Analytics Workspace.
* Performed security investigations using Kusto Query Language (KQL) in Microsoft Sentinel.
Sumo Logic SIEM
* Investigated correlated security incidents.
* Pivoted across authentication logs and security events.
* Identified attack patterns, validated evidence, and documented findings.
Wireshark
* Analyzed packet captures (PCAPs) to identify protocols, network communications, and suspicious activity.
Phishing Analysis
* Investigated phishing emails by analyzing:
* Email headers
* Sender reputation and infrastructure
* URLs and attachments
* File reputation
* Indicators of Compromise (IOCs)
Suricata
* Developed and validated basic IDS rules to detect simulated malicious network activity.
⸻
Technical Skills
Security
* Microsoft Defender for Endpoint
* Microsoft Sentinel
* Sumo Logic SIEM
* Wireshark
* Suricata
* MITRE ATT&CK
* Kusto Query Language (KQL)
* Phishing Analysis
* IOC Analysis
* Basic Incident Response
Microsoft Technologies
* Microsoft Intune
* Microsoft Entra ID
* Exchange Online
* Microsoft 365
* Azure Arc
* Conditional Access
* Microsoft Defender
Networking
* TCP/IP
* DNS
* DHCP
* HTTP/HTTPS
* VPN
* Basic Routing & Switching
* Network Troubleshooting
Certifications
* CompTIA A+
* Cisco CCNA (In Progress)
Similar candidates
-
Аналітик продажів
Remote -
Аналітик
Remote -
Data-аналітик
Remote, Kharkiv -
Аналітик баз даних
Remote, Kyiv -
Data scientist
Remote, Kyiv, Kharkiv -
Аналітик, Data Analyst (1С, BAS, Excel, SQL)
40000 UAH, Remote, Chernihiv