Security Operations Analyst (L1)
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked just now — checked against the employer's own applicant tracking system, which is the company answering directly.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 3h ago
The date the source published, not the day we noticed it (2026-09-16). Last seen at its source 1h ago.
Is it remote?
The listing says yes
The location field doesn't say remote, so our assessment is based on the title or the description. Read the listing before applying.
Who may apply?
Europe
The description states no restriction of its own. This is the source's own tag.
Pay not stated
Similar roles pay £75k–104.8k/yr
Middle 50% of 13 listings that do state pay — Operations · all levels · Europe · GBP/year. This employer has published no salary; this is what comparable listings we hold disclose, never converted between currencies or periods. How this is calculated.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
greenhouse employer's own board first seen 1h ago · last seen 1h ago
The listing
We are inviting you, a highly motivated and results-oriented Security Operations Analyst to join our team on a full-time basis.
Our team has unique expertise in research, analysis, and product development. By relying on technical insights and a data-driven approach, we create disruptive future-defining innovations of the fin-tech industry that remain our basis for success.
Responsibilities
- Monitor prioritized alert queues and validate whether alerts indicate real risk
- Enrich cases and correlate relevant endpoint, identity, authentication, network, service, asset, user, timeline, and business context
- Perform initial investigations, classify alerts, assess preliminary severity and scope, and document the evidence and reasoning in the case-management system
- Close false positives and execute approved low-risk actions only through defined runbooks
- Escalate suspected incidents, privileged-account issues, and high-impact or production-impact cases to L2, the manager, or Incident Response
- Maintain clear handover notes and support improvements to case quality and runbooks
Requirements
- Hands-on experience with security alert triage through work, an internship, or a practical lab, including use of at least one SIEM and exposure to EDR or XDR and case-management workflows
- Ability to build basic searches or queries, filter security events, and correlate related activity across more than one data source (Experience with basic SIEM query languages such as KQL, EQL)
- Ability to interpret common endpoint, identity, authentication, network, DNS, HTTP, and service or cloud audit telemetry at an initial-investigation level
- Working fundamentals of Windows and Linux, TCP/IP, DNS, HTTP, authentication, access control, and common attack patterns such as phishing, credential abuse, malware execution, and suspicious account activity
- Ability to distinguish true positives, false positives, and benign activity; assign a preliminary severity; identify affected users or assets; and recognize when scope or impact is uncertain
- Basic use of indicators of compromise, reputation sources, and threat-intelligence context, with awareness of the MITRE ATT&CK framework
- Ability to create a concise investigation timeline and document evidence, actions, conclusions, and handover or escalation notes in a case-management system
- Ability to follow approved runbooks, perform only authorized low-risk actions, recognize the limits of L1 authority, and escalate suspected incidents correctly
Will be a plus
- Simple Python or PowerShell scripts for investigation and enrichment
- Exposure to cloud, email-security, or SaaS audit logs and common phishing-investigation workflows
- Practical cybersecurity labs or an entry-level certification such as Security+ or CySA+
- Experience with MacOS
We offer
- Tax expenses coverage for private entrepreneurs in Ukraine
- Expert support and guidance for Ukrainian private entrepreneurs
- 20 paid vacation days per year
- 10 paid sick leave days per year
- Public holidays as per the company's approved Public holiday list
- Medical insurance
- Opportunity to work remotely
- Professional education budget
- Language learning budget
- Wellness budget (gym membership, sports gear and related expenses)
Role mission
JustMarkets needs consistent, trustworthy first-line defense against real security threats in a high-availability financial environment. This role exists to triage prioritized alerts accurately and within SLA, build evidence-based cases by correlating context across endpoint, identity, network, and service data, and route suspected incidents, privileged-account issues, and high-impact cases to L2 or Incident Response without delay — while executing only approved, low-risk actions and handing off clean, well-documented cases that let the wider Security Operations team act with confidence.
Requirements hard skills
- Hands-on experience with security alert triage through work, an internship, or a practical lab, including use of at least one SIEM and exposure to EDR or XDR and case-management workflows.
- Ability to build basic searches or queries, filter security events, and correlate related activity across more than one data source.
- Ability to interpret common endpoint, identity, authentication, network, DNS, HTTP, and service or cloud audit telemetry at an initial-investigation level.
- Working fundamentals of Windows and Linux, TCP/IP, DNS, HTTP, authentication, access control, and common attack patterns such as phishing, credential abuse, malware execution, and suspicious account activity.
- Ability to distinguish true positives, false positives, and benign activity; assign a preliminary severity; identify affected users or assets; and recognize when scope or impact is uncertain.
- Basic use of indicators of compromise, reputation sources, and threat-intelligence context, with awareness of the MITRE ATT&CK framework.
- Ability to create a concise investigation timeline and document evidence, actions, conclusions, and handover or escalation notes in a case-management system.
- Ability to follow approved runbooks, perform only authorized low-risk actions, recognize the limits of L1 authority, and escalate suspected incidents correctly.
Requirements soft skills
- Strong attention to detail and evidence quality.
- Analytical and critical thinking in standard investigation scenarios.
- Integrity, discipline, and sound judgment when handling security actions.
- Clear written and verbal communication, including concise escalation and handover notes.
- Ownership of assigned cases, willingness to learn, and effective collaboration with L2, Incident Response, IT Operations, IAM, Platform, and Product Support.
Responsibilities
- Monitor prioritized alert queues and validate whether alerts indicate real risk.
- Enrich cases and correlate relevant endpoint, identity, authentication, network, service, asset, user, timeline, and business context.
- Perform initial investigations, classify alerts, assess preliminary severity and scope, and document the evidence and reasoning in the case-management system.
- Close false positives and execute approved low-risk actions only through defined runbooks.
- Escalate suspected incidents, privileged-account issues, and high-impact or production-impact cases to L2, the manager, or Incident Response.
- Maintain clear handover notes and support improvements to case quality and runbooks.
Will be a plus
- Experience with basic SIEM query languages such as KQL, EQL.
- simple Python or PowerShell scripts for investigation and enrichment.
- Exposure to cloud, email-security, or SaaS audit logs and common phishing-investigation workflows.
- Practical cybersecurity labs or an entry-level certification such as Security+ or CySA+.