The Mediafon Technology team develops and delivers SOCaaS solutions. Our mission is simple: to make high-level cybersecurity accessible to businesses that want to grow quickly and securely.
We are expanding our SOC capabilities and are looking for an analyst who is interested in not only putting a tick on an alert, but also understanding the real context – what is happening in the client’s environment and how to stop it.
We may be looking for you.
What will you do with us?
Monitor and analyze security events from various sources (SIEM, EDR, network equipment), look for anomalies and real threats
Perform alert triage, identify IOCs, assess risk and incident context
Work according to SOPs, playbooks and contribute to their development
Collaborate with the SOC team, engineers and customers to resolve incidents
Contribute to the improvement of SOC processes, automation and tools
Professional requirements:
Higher IT education in information systems, cybersecurity or related fields
1-2 years of experience in cybersecurity, IT infrastructure or systems administration
Entry-level cybersecurity qualification (one of): CompTIA Security+, Microsoft SC-900 / SC-200, CEH (entry-level), eJPT, Blue Team Level 1 or equivalent
Technological competencies:
Networks and Infrastructure:
Understanding of TCP/IP, DNS, DHCP, HTTP/HTTPS principles
Basic understanding of how network components (e.g. firewall) participate in a security context
Operating Systems:
Windows: Event Viewer, Active Directory basics, PowerShell basics
Linux (advantage): syslog, file structure, basic commands
Working with security tools and incidents:
Ability to analyze Windows Event Logs, Firewall logs, authentication incidents, endpoint alerts
Understanding of false positive / false negative, alert triage, IOC identification
Experience working with at least one SIEM platform (e.g. Wazuh, Microsoft Sentinel, Splunk, QRadar)
Incident filtering and correlation, use of queries, incident chain analysis
Understanding of incident lifecycle, working according to SOPs and playbooks
Understanding of MITRE ATT&CK basics
Analytical competencies:
Ability to distinguish real incident from noise
Critical thinking when evaluating alert context
Logical analysis skills when correlating multiple events
Determining the risk level (Low / Medium / High)
Desired knowledge:
SOAR or automation basics
Python or PowerShell scripting basics
Understanding of NIS2, ISO 27001, DORA
Cloud security knowledge (Azure / AWS)
Understanding of EDR/XDR solutions (MS Defender, CrowdStrike, Check Point, etc.)
What you will find with us:
The ability to work on real incidents and grow faster than in traditional SOCs
Flexibility, learning budget and certification support
An environment where you can grow into a Mid or Senior role
Actively applied artificial intelligence solutions in daily activities
Freedom to work in the way that is most convenient for you - in an office in the center or in a hybrid way
Mediafon is a technology group of companies providing cybersecurity, telecommunications and IT solutions to businesses and government institutions in Lithuania and abroad. We work with international partners, value initiative and encourage improvement.