• File

Денис

SOC L1 Analyst

Age:
25 years
City of residence:
Kyiv
Ready to work:
Remote

Contact information

The job seeker has provided: Phone numberEmail

Name, contacts and photo are only available to registered employers. To access the candidates' personal information, log in as an employer or sign up.

Uploaded file

Quick view version

This resume is posted as a file. The quick view option may be worse than the original resume.

Denys Sirchenko
[open contact info](look above in the "contact info" section) · Email: [open contact info](look above in the "contact info" section) · Telegram: @ikekykss

SOC L1 ANALYST
Results-oriented SOC L1 Analyst with hands-on experience in real-time security monitoring, incident triage,
and access control across hybrid environments. Successfully monitored 500+ Linux
infrastructure/database servers and 3,000+ employee endpoints using Splunk, Wazuh, SentinelOne, and
Cloudflare. Proven track record of rapid threat detection (<5 minutes for DDoS attacks) and strict SLA
compliance (MTTA 1–10 min, MTTE 5–15 min).

TECHNICAL SKILLS & COMPETENCIES
SIEM & Monitoring: Splunk, Wazuh, SentinelOne (Pre-configured Dashboards)
Network & Cloud Security: Cloudflare, AWS WAF, AWS IAM, SSH Access Management, Network Traffic
Analysis
Security Operations & Response: Incident Handling & Escalation, DLP Slack Alerts, Phishing Campaign
Management
Tools & Systems: Linux, macOS, Jira, Confluence, Wireshark, VirtualBox

PROFESSIONAL EXPERIENCE
Red Core Jan 2024 - Oct 2025
SOC L1 Operator
Monitored security operations and processed 200+ monthly security alerts across a hybrid infrastructure of
500+ Linux servers and 3,000+ employee endpoints via SentinelOne, Splunk, and Wazuh.
Maintained strict incident response targets, consistently achieving MTTA of 1–10 minutes and MTTE of 5–
15 minutes.
Handled 200–300 Jira tickets monthly (access management, automated SIEM alerts, traffic checks) and
escalated up to 50 critical incidents to Tier 2 engineers and SecDevOps.
Detected 5–6 major DDoS attacks within the first 5 minutes of onset using Cloudflare traffic analysis and
AWS WAF metric tracking.
Spearheaded internal phishing awareness campaigns, reducing phishing link click rates from 40% to 8–10%
in targeted non-technical teams.
Monitored custom Slack-integrated DLP alerts to prevent credential leaks and unauthorized exposure of
confidential documents.
Authored comprehensive SOC L1 Standard Operating Procedures (SOPs) in Confluence for phishing
campaign execution.

EDUCATION
TryHackMe (TryHackMe.com) Feb 2026 - Oct 2026
Blue Team (SOC) Path
TryHackMe (TryHackMe.com) Aug 2023 - Dec 2023
Penetration Testing Path
KFKTE NAU, Kyiv Sep 2016 - Jun 2020
Junior Software Engineering Specialist

LANGUAGES
Ukrainian: Native
English: B1 (Intermediate)

Similar candidates

All similar candidates


Compare your requirements and salary with other companies' jobs: