SEE ALL VACANCIES

Security Analyst

Vacancy details
Information Security
Security Analyst
Middle
Ukraine
Remote
APPLY NOW
REFER A FRIEND

With more than 20 years of market experience, Intellias brings together technologists, creators, and innovators across Europe, North and Latin America, and the Middle East. Join our international team and help us solve the challenges of tomorrow.

What project we have for you

We are looking for a proactive and detail-oriented Security Analyst to strengthen our Information Security function and help safeguard our business operations. In this role, you will investigate security incidents, develop and improve detection capabilities, automate repetitive operational work and contribute to the ongoing development of our SOC technology and processes. You will work across Microsoft 365, endpoint, identity and infrastructure security, using Microsoft Defender XDR, ELK, Wazuh, TheHive and Cortex. A significant part of the role focuses on reducing manual analyst effort through SOAR workflows, scripting and API-driven integrations.

You will play a key role in maintaining and enhancing Intellias’ security posture while supporting ISO 27001 and ISO 27017 compliance initiatives and audits.

The position includes standard working hours and participation in an on-call rotation covering nights and weekends.

What you will do

  • Design, implement and continuously improve SOAR workflows using TheHive, Cortex and other security platforms.
  • Develop PowerShell and Python scripts for investigation, enrichment, reporting and security-response automation.
  • Integrate security platforms, business systems and third-party tools through APIs and other available interfaces.
  • Identify manual SOC processes suitable for automation and implement solutions that improve operational efficiency and reduce analyst workload.
  • Develop, test and tune SIEM detection rules, correlation logic and alerting mechanisms.
  • Conduct threat-hunting activities and identify gaps in detection coverage and security visibility.
  • Monitor, analyse and investigate security events and incidents across Microsoft 365, identity, endpoint, email and infrastructure environments.
  • Perform advanced alert triage, incident containment and remediation coordination.
  • Perform phishing investigations, access reviews and device-compliance investigations.
  • Process operational security requests and investigate security-tool and platform failures.
  • Support vulnerability management and remediation activities related to identified risks and security incidents.
  • Maintain and improve incident-response procedures, analyst playbooks, automation workflows and technical documentation.
  • Prepare security metrics, reports and evidence required for ISO 27001, ISO 27017, customer and internal audits.
  • Participate in the on-call rotation for critical security incidents.
  • Continuously improve SOC processes, detections, integrations and automation capabilities.

What you need for this

  • At least 3 years of practical experience in security operations, incident response, security monitoring or a similar technical security role.
  • Hands-on experience investigating security events and incidents beyond initial alert triage.
  • Strong practical knowledge of:
    • Microsoft 365 security
    • Microsoft Defender XDR
    • Elasticsearch, Logstash and Kibana
    • Wazuh
    • TheHive
    • Cortex
  • Experience developing SIEM detection rules, correlation logic and investigation queries.
  • Experience tuning security detections and reducing false positives.
  • Advanced PowerShell or Python scripting skills.
  • Practical experience integrating systems through APIs.
  • Experience designing or implementing SOAR workflows and automated security-response actions.
  • Understanding of endpoint, identity, email, network and cloud-security monitoring.
  • Knowledge of incident-response processes, evidence handling and remediation coordination.
  • Experience analysing logs from multiple systems and correlating activity across different data sources.
  • Understanding of common attacker techniques and security frameworks such as MITRE ATT&CK.
  • Ability to document technical findings clearly and provide practical remediation recommendations.
  • Ability to manage several operational cases while maintaining clear priorities and investigation records.
  • A university degree in computer science, Information Security, or a related field.
  • Strong analytical and problem-solving skills.
  • Excellent written and verbal communication skills.
  • Ability to work independently and as part of a team.
  • English at upper-intermediate level or higher.

Will be a plus:

  • Experience building or improving SOC capabilities rather than only operating existing tools.
  • Relevant certifications such as CompTIA Security+, CySA+, CSA, CISSP.
  • Knowledge of recognised SOC frameworks and operating models, including NIST guidance for Security Operations Centres.
  • Experience with cloud security (e.g., Azure, AWS).
  • Familiarity with regulatory requirements and standards (e.g., GDPR, HIPAA).
  • Experience with Jira, service-management platforms or PagerDuty.

What it’s like to work at Intellias

At Intellias, where technology takes center stage, people always come before processes. By creating a comfortable atmosphere in our team, we empower individuals to unlock their true potential and achieve extraordinary results. That’s why we offer a range of benefits that support your well-being and charge your professional growth.
We are committed to fostering equity, diversity, and inclusion as an equal opportunity employer. All applicants will be considered for employment without discrimination based on race, color, religion, age, gender, nationality, disability, sexual orientation, gender identity or expression, veteran status, or any other characteristic protected by applicable law.
We welcome and celebrate the uniqueness of every individual. Join Intellias for a career where your perspectives and contributions are vital to our shared success.

Have not found the most
suitable position yet?
Leave your resume and we will select a cool option for you.
Find me a job
Good news!
Link copied
Good news!
You did it.
Bad news!
Something went wrong. Please try again.