Stanislav

SOC Analyst T1

Розглядає посади:
SOC Analyst T1, Фахівець з інформаційної безпеки
Місто проживання:
Івано-Франківськ
Готовий працювати:
Дистанційно

Контактна інформація

Шукач вказав телефон .

Прізвище, контакти та світлина доступні тільки для зареєстрованих роботодавців. Щоб отримати доступ до особистих даних кандидатів, увійдіть як роботодавець або зареєструйтеся.

Досвід роботи

L1 IT Operations Enginner

з 01.2026 по нині (8 місяців)
Diya, Дистанційно (IT)

Managed user accounts, mailbox permissions, shared mailboxes, distribution lists, and mail flow troubleshooting in Microsoft Exchange Online and Microsoft Entra ID.
* Administered Microsoft 365 identities, licensing, and user access.
* Troubleshot Microsoft Intune device enrollment, Autopilot provisioning, compliance status, and synchronization issues between Intune and Microsoft Entra ID.
* Investigated device compliance issues and verified remediation through Microsoft Intune and Microsoft 365 administration portals.
* Performed initial Microsoft Defender for Endpoint investigations by reviewing device timelines, alerts, process trees, file hashes, command-line activity, and alert evidence prior to escalation.
* Conducted phishing investigations by analyzing email headers, sender reputation, domains, URLs, attachments, and indicators of compromise (IOCs).
* Investigated suspicious authentication activity involving Microsoft Entra ID, Conditional Access, MFA, Outlook, Teams, and Exchange Online.
* Supported endpoint administration, software deployment, remote troubleshooting, and user onboarding/offboarding within Microsoft 365 environments.
* Collaborated with senior engineers to investigate security-related incidents and perform initial alert triage.

Знання і навички

  • Microsoft 365
  • Active Directory
  • PowerShell
  • DHCP
  • DNS settings
  • Windows Server Administration
  • Maintenance of technical documentation
  • Troubleshooting

Додаткова інформація

Security Projects & Hands-on Experience

Microsoft Defender for Endpoint

* Investigated endpoint alerts using device timelines, process trees, file hashes, command-line activity, authentication events, and MITRE ATT&CK mappings.
* Performed initial malware triage and documented investigation findings.

Microsoft Sentinel & Azure Arc

* Onboarded Windows endpoints to Azure Arc.
* Configured log collection through Azure Log Analytics Workspace.
* Performed security investigations using Kusto Query Language (KQL) in Microsoft Sentinel.

Sumo Logic SIEM

* Investigated correlated security incidents.
* Pivoted across authentication logs and security events.
* Identified attack patterns, validated evidence, and documented findings.

Wireshark

* Analyzed packet captures (PCAPs) to identify protocols, network communications, and suspicious activity.

Phishing Analysis

* Investigated phishing emails by analyzing:
* Email headers
* Sender reputation and infrastructure
* URLs and attachments
* File reputation
* Indicators of Compromise (IOCs)

Suricata

* Developed and validated basic IDS rules to detect simulated malicious network activity.



Technical Skills

Security

* Microsoft Defender for Endpoint
* Microsoft Sentinel
* Sumo Logic SIEM
* Wireshark
* Suricata
* MITRE ATT&CK
* Kusto Query Language (KQL)
* Phishing Analysis
* IOC Analysis
* Basic Incident Response

Microsoft Technologies

* Microsoft Intune
* Microsoft Entra ID
* Exchange Online
* Microsoft 365
* Azure Arc
* Conditional Access
* Microsoft Defender

Networking

* TCP/IP
* DNS
* DHCP
* HTTP/HTTPS
* VPN
* Basic Routing & Switching
* Network Troubleshooting

Certifications

* CompTIA A+
* Cisco CCNA (In Progress)

Схожі кандидати

Усі схожі кандидати


Порівняйте свої вимоги та зарплату з вакансіями інших підприємств: