← back to jobs
> job detail
I
👽Other

L1 SOC Analyst

Integrity360 · Sofia, Bulgaria
// classified as
Other (Adjacent or hard to classify.)
posted
1d ago
location
Sofia, Bulgaria
languages
tools
> description

Title: Level 1 SOC Analyst

Location: Sofia, on site

Work Hours: Shift pattern

Job type: Full-Time Permanent

Salary: Negotiable / DOE

 

 

About Us


Integrity360 is a leading independent cybersecurity and PCI specialist operating across Europe, Africa, the Caribbean, and North America. The company has office locations in Ireland, the UK, Bulgaria, Italy, Sweden, Spain, Lithuania, Ukraine, Africa, the Caribbean, and Canada, supported by seven Security Operations Centres (SOCs) located in Dublin, Sofia, Madrid, Stockholm, Rome, Johannesburg and Cape Town.

With over 780 employees, including more than 585 dedicated cybersecurity professionals, Integrity360 delivers a full suite of professional, support, and managed security services. These span the complete cyber risk lifecycle, from identification and prevention to detection, response, and recovery. Integrity360 supports over 3000 mid-market and enterprise organisations across sectors including financial services, insurance, government, healthcare, retail, telecommunications, and utilities.

At Integrity360, people come first. We invest heavily in learning, development and progression, fostering a dynamic culture where innovation, collaboration and continuous growth are at the heart of what we do. If you're ready to take your cyber security career to the next level, we’d love to hear from you.

 

 

Job Role / Responsibilities



As a Level 1 SOC Analyst, you will act as the first line of defense, responsible for continuous monitoring, triage, and initial investigation of security events. This role is critical in maintaining security posture and ensuring only high-quality, actionable alerts progress through the SOC pipeline.



Primary Duties/Responsibilities include:

  • Monitor security events across our security ecosystem, including:
    • Microsoft Sentinel
    • Microsoft Defender for Endpoint
    • Defender for Identity
    • Defender for Office365
    • Defender for Cloud Apps
  • Perform alert triage with clear analytical judgement:
    • Validate alerts
    • Assign appropriate severity
    • Provide full investigative context before escalation
  • Conduct preliminary investigations:
    • Identify IOCs, affected systems, attack vectors and potential business impact
    • Apply frameworks such as MITRE ATT&CK, Cyber Kill Chain, and NIST IR lifecycle
  • Maintain high-quality documentation and case notes within ServiceNow SIR
  • Communicate effectively with internal teams and client stakeholders
  • Contribute to continuous improvement through feedback, tuning suggestions, and knowledge sharing
  • Demonstrate strong commitment to ongoing professional development
  • SLA handling/management - Aspire to manage security events in accordance with applicable (response and resolution) SLA’s.



Desired Skills

  • Demonstrable experience in IT or cybersecurity support, ideally within a SOC or monitoring environment
  • Solid understanding of cybersecurity fundamentals and CIA principles
  • Familiarity with SIEM, EDR/XDR, log analysis, and security monitoring workflows
  • Working knowledge of MITRE ATT&CK and NIST IR processes
  • Strong analytical and investigative thinking
  • Excellent written and verbal communication skills
  • Ability to operate independently within Tier 1 scope
  • Fluent in English
  • Ability to work effectively in a fast-paced environment and prioritize tasks accordingly

 

Certifications/Qualifications (preferred but not required)

  • CompTIA Security+, ISC2, ISACA, SANS or equivalent
  • GIAC Security essentials (GSEC)
  • Blueteam security level 1



#LI-JL1