Teknologji Informacioni (IT)Prishtinë3 javë më parëFull Time
Position Summary
Sentry is looking to add a Senior Security Operations Center (SOC) Analyst to its Cyber Security team. The person selected for this role will be responsible for observing, identifying, examining, and handling security incidents in hybrid and cloud-native environments. The role is centered on safeguarding cloud infrastructure, strengthening detection functions, guiding advanced incident investigations, and improving the organization’s overall security posture through threat hunting, detection engineering, and security automation.
The preferred candidate brings strong experience with SIEM platforms such as Elastic Security and Splunk, solid expertise in cloud security, and the capability to investigate advanced threats affecting endpoints, identities, networks, and cloud workloads.
Key Responsibilities
Oversee and analyze security events across cloud infrastructure, endpoints, identity systems, and enterprise applications by using Elastic Security, Splunk, Wazuh, and other monitoring solutions.
Direct the investigation, containment, elimination, and recovery phases of complex cybersecurity incidents.
Conduct proactive threat hunting by using telemetry from cloud environments, endpoints, identity providers, and network security controls.
Build, refine, and sustain SIEM detection rules, correlation searches, dashboards, and alerting logic to increase detection precision and minimize false positives.
Produce and improve detection content in line with the MITRE ATT&CK framework and current threat intelligence.
Examine cloud-related security events, including identity compromise, privilege escalation, attacks on workloads, container security incidents, and cloud misconfigurations.
Review authentication logs, API activity, network traffic, endpoint telemetry, and cloud audit logs in order to detect malicious actions and indicators of compromise.
Work closely with cloud, infrastructure, and DevOps teams to investigate and resolve security findings.
Contribute to incident response tasks such as collecting forensic data, preserving evidence, performing root cause analysis, and documenting lessons learned.
Prepare and maintain SOC playbooks, investigation procedures, and operational documentation.
Help onboard new log sources and security telemetry into SIEM platforms.
Take part in purple team exercises, adversary emulation activities, and validation of detection capabilities.
Support junior analysts through mentorship and technical guidance during investigations.
Participate in ongoing SOC improvement efforts, including automation, workflow enhancement, and detection engineering.
Required Qualifications
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or comparable practical experience.
Teknologji Informacioni (IT)Prishtinë3 javë më parëFull Time
Position Summary
Sentry is looking to add a Senior Security Operations Center (SOC) Analyst to its Cyber Security team. The person selected for this role will be responsible for observing, identifying, examining, and handling security incidents in hybrid and cloud-native environments. The role is centered on safeguarding cloud infrastructure, strengthening detection functions, guiding advanced incident investigations, and improving the organization’s overall security posture through threat hunting, detection engineering, and security automation.
The preferred candidate brings strong experience with SIEM platforms such as Elastic Security and Splunk, solid expertise in cloud security, and the capability to investigate advanced threats affecting endpoints, identities, networks, and cloud workloads.
Key Responsibilities
Oversee and analyze security events across cloud infrastructure, endpoints, identity systems, and enterprise applications by using Elastic Security, Splunk, Wazuh, and other monitoring solutions.
Direct the investigation, containment, elimination, and recovery phases of complex cybersecurity incidents.
Conduct proactive threat hunting by using telemetry from cloud environments, endpoints, identity providers, and network security controls.
Build, refine, and sustain SIEM detection rules, correlation searches, dashboards, and alerting logic to increase detection precision and minimize false positives.
Produce and improve detection content in line with the MITRE ATT&CK framework and current threat intelligence.
Examine cloud-related security events, including identity compromise, privilege escalation, attacks on workloads, container security incidents, and cloud misconfigurations.
Review authentication logs, API activity, network traffic, endpoint telemetry, and cloud audit logs in order to detect malicious actions and indicators of compromise.
Work closely with cloud, infrastructure, and DevOps teams to investigate and resolve security findings.
Contribute to incident response tasks such as collecting forensic data, preserving evidence, performing root cause analysis, and documenting lessons learned.
Prepare and maintain SOC playbooks, investigation procedures, and operational documentation.
Help onboard new log sources and security telemetry into SIEM platforms.
Take part in purple team exercises, adversary emulation activities, and validation of detection capabilities.
Support junior analysts through mentorship and technical guidance during investigations.
Participate in ongoing SOC improvement efforts, including automation, workflow enhancement, and detection engineering.
Required Qualifications
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or comparable practical experience.
At least 5 years of experience in a Security Operations Center (SOC), Incident Response, or Cybersecurity Operations position.
Strong practical experience with Elastic Security and/or Splunk Enterprise Security.
Background in investigating security incidents in cloud-native and hybrid environments.
Strong understanding of cloud platforms, including AWS, Microsoft Azure, and/or Google Cloud Platform.
Experience monitoring cloud audit logs such as AWS CloudTrail, Azure Activity Logs, Microsoft Entra ID logs, and Kubernetes audit logs.
Strong knowledge of Windows, Linux, Active Directory, Microsoft Entra ID, networking, and identity security.
Solid understanding of attack methods, adversary tactics, and the MITRE ATT&CK framework.
Experience conducting log analysis across operating systems, applications, cloud services, and network infrastructure.
Proficiency in writing SIEM queries with Splunk SPL and Elasticsearch Query Language (ES|QL/KQL or Lucene syntax as applicable).
Experience with scripting or automation in Python, PowerShell, or Bash.
Strong analytical, troubleshooting, and communication abilities.
Preferred Qualifications
Experience in securing Kubernetes, Docker, and containerized workloads.
Experience with Infrastructure as Code tools such as Terraform, CloudFormation, or ARM/Bicep.
Familiarity with cloud security services including AWS GuardDuty, Azure Defender, Microsoft Defender for Cloud, AWS Security Hub, or Google Security Command Center.
Experience with SOAR platforms and security automation.
Familiarity with CI/CD security, DevSecOps practices, and application security monitoring.
Knowledge of threat intelligence platforms, IOC management, and malware analysis.
The role is expected to begin as soon as possible after the selection process is completed.
Employment Type
Full-time.
Required documents
CV
Cover letter
Up to three professional references
At least 5 years of experience in a Security Operations Center (SOC), Incident Response, or Cybersecurity Operations position.
Strong practical experience with Elastic Security and/or Splunk Enterprise Security.
Background in investigating security incidents in cloud-native and hybrid environments.
Strong understanding of cloud platforms, including AWS, Microsoft Azure, and/or Google Cloud Platform.
Experience monitoring cloud audit logs such as AWS CloudTrail, Azure Activity Logs, Microsoft Entra ID logs, and Kubernetes audit logs.
Strong knowledge of Windows, Linux, Active Directory, Microsoft Entra ID, networking, and identity security.
Solid understanding of attack methods, adversary tactics, and the MITRE ATT&CK framework.
Experience conducting log analysis across operating systems, applications, cloud services, and network infrastructure.
Proficiency in writing SIEM queries with Splunk SPL and Elasticsearch Query Language (ES|QL/KQL or Lucene syntax as applicable).
Experience with scripting or automation in Python, PowerShell, or Bash.
Strong analytical, troubleshooting, and communication abilities.
Preferred Qualifications
Experience in securing Kubernetes, Docker, and containerized workloads.
Experience with Infrastructure as Code tools such as Terraform, CloudFormation, or ARM/Bicep.
Familiarity with cloud security services including AWS GuardDuty, Azure Defender, Microsoft Defender for Cloud, AWS Security Hub, or Google Security Command Center.
Experience with SOAR platforms and security automation.
Familiarity with CI/CD security, DevSecOps practices, and application security monitoring.
Knowledge of threat intelligence platforms, IOC management, and malware analysis.