Stanislav
SOC Analyst T1
- Розглядає посади:
- SOC Analyst T1, Фахівець з інформаційної безпеки
- Місто проживання:
- Івано-Франківськ
- Готовий працювати:
- Дистанційно
Контактна інформація
Шукач вказав телефон .
Прізвище, контакти та світлина доступні тільки для зареєстрованих роботодавців. Щоб отримати доступ до особистих даних кандидатів, увійдіть як роботодавець або зареєструйтеся.
Отримати контакти цього кандидата можна на сторінці https://www.work.ua/resumes/19740076/
Досвід роботи
L1 IT Operations Enginner
з 01.2026 по нині
(8 місяців)
Diya, Дистанційно (IT)
Managed user accounts, mailbox permissions, shared mailboxes, distribution lists, and mail flow troubleshooting in Microsoft Exchange Online and Microsoft Entra ID.
* Administered Microsoft 365 identities, licensing, and user access.
* Troubleshot Microsoft Intune device enrollment, Autopilot provisioning, compliance status, and synchronization issues between Intune and Microsoft Entra ID.
* Investigated device compliance issues and verified remediation through Microsoft Intune and Microsoft 365 administration portals.
* Performed initial Microsoft Defender for Endpoint investigations by reviewing device timelines, alerts, process trees, file hashes, command-line activity, and alert evidence prior to escalation.
* Conducted phishing investigations by analyzing email headers, sender reputation, domains, URLs, attachments, and indicators of compromise (IOCs).
* Investigated suspicious authentication activity involving Microsoft Entra ID, Conditional Access, MFA, Outlook, Teams, and Exchange Online.
* Supported endpoint administration, software deployment, remote troubleshooting, and user onboarding/offboarding within Microsoft 365 environments.
* Collaborated with senior engineers to investigate security-related incidents and perform initial alert triage.
Знання і навички
- Microsoft 365
- Active Directory
- PowerShell
- DHCP
- DNS settings
- Windows Server Administration
- Maintenance of technical documentation
- Troubleshooting
Додаткова інформація
Security Projects & Hands-on Experience
Microsoft Defender for Endpoint
* Investigated endpoint alerts using device timelines, process trees, file hashes, command-line activity, authentication events, and MITRE ATT&CK mappings.
* Performed initial malware triage and documented investigation findings.
Microsoft Sentinel & Azure Arc
* Onboarded Windows endpoints to Azure Arc.
* Configured log collection through Azure Log Analytics Workspace.
* Performed security investigations using Kusto Query Language (KQL) in Microsoft Sentinel.
Sumo Logic SIEM
* Investigated correlated security incidents.
* Pivoted across authentication logs and security events.
* Identified attack patterns, validated evidence, and documented findings.
Wireshark
* Analyzed packet captures (PCAPs) to identify protocols, network communications, and suspicious activity.
Phishing Analysis
* Investigated phishing emails by analyzing:
* Email headers
* Sender reputation and infrastructure
* URLs and attachments
* File reputation
* Indicators of Compromise (IOCs)
Suricata
* Developed and validated basic IDS rules to detect simulated malicious network activity.
⸻
Technical Skills
Security
* Microsoft Defender for Endpoint
* Microsoft Sentinel
* Sumo Logic SIEM
* Wireshark
* Suricata
* MITRE ATT&CK
* Kusto Query Language (KQL)
* Phishing Analysis
* IOC Analysis
* Basic Incident Response
Microsoft Technologies
* Microsoft Intune
* Microsoft Entra ID
* Exchange Online
* Microsoft 365
* Azure Arc
* Conditional Access
* Microsoft Defender
Networking
* TCP/IP
* DNS
* DHCP
* HTTP/HTTPS
* VPN
* Basic Routing & Switching
* Network Troubleshooting
Certifications
* CompTIA A+
* Cisco CCNA (In Progress)
Схожі кандидати
-
Маркетинг-аналітик
Дистанційно -
Аналітик продажів
Дистанційно -
Аналітик
Дистанційно -
Data-аналітик
Дистанційно, Харків -
Аналітик баз даних
Дистанційно, Київ -
Data scientist
Дистанційно, Київ, Харків