Logo for KVG

L1 SOC ANALYST

Role overview

Qualifications

  • 1+ year in IT support, service desk, systems administration, or a security operations role.
  • Working knowledge of Microsoft 365 and a cloud-first or hybrid environment.
  • Networking and mail flow fundamentals: TCP/IP, DNS, SMTP, MX records, VPN, firewall concepts.
  • Understanding of common attack techniques: phishing, credential theft, MFA fatigue, token theft, malware delivery.

Responsibilities

  • Monitor and triage incidents in Microsoft Sentinel and Microsoft Defender XDR.
  • Decide whether an alert is a true positive, a false positive, or benign.
  • Review the Defender for Office 365 quarantine and handle user-reported phishing.
  • Keep case records that hold up under audit and hand over cleanly at the end of each shift.

Key facts

Hard skills

Other skills

  • Communication

About the company

KVG logo

KVG

Import & Export Trade

KVG is a proven mission support provider internationally recognized for innovative, creative, and cost-efficient support solutions. With a strong presence at the front lines of defense activities worldwide, the KVG team excels at dynamic project execution support in rugged, austere, and challenging locations. Respected for our ability to make it happen and get it done, KVG retains responsible, inventive and versatile operators from across the globe. They are located in the places where projects become challenging. We are recognized as the go-to problem solving team for mission support on the edge.

Company details

Company typeSME
IndustryImport & Export Trade
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

About The Role

KVG is looking for an L1 SOC Analyst to become the first line of security monitoring for a Microsoft-based environment spanning Moldova, Romania, Ukraine, Germany, Spain, the Philippines, and the United States. You will own the daily triage of alerts in Microsoft Sentinel and Microsoft Defender XDR, and the review of the Microsoft 365 email quarantine - deciding what is real, what is noise, and what needs to go up the chain.

This is a structured entry point into security operations. You will work to documented runbooks and a clear action mandate, alongside our Cloud Security Engineer, in an environment with genuine compliance weight behind it (NIST SP 800-171 and CMMC 2.0). We fund your certification path and expect you to grow into L2 analysis.

What You Will Do

  • Monitor and triage incidents in Microsoft Sentinel and Microsoft Defender XDR, working in order of severity.
  • Decide whether an alert is a true positive, a false positive, or benign - and write down why.
  • Review the Defender for Office 365 quarantine, handle user-reported phishing, and action release or block decisions.
  • Analyse message headers, SPF/DKIM/DMARC results, URLs, and attachments to reach a defensible verdict.
  • Run pre-built KQL queries in Advanced Hunting to work out who and what was affected.
  • Apply runbook-defined containment: revoke sessions, block sign-in, isolate a device, purge a delivered message.
  • Escalate anything beyond your mandate with a clear timeline, the evidence, and what you already did.
  • Keep case records that hold up under audit, and hand over cleanly at the end of each shift.
  • Flag noisy detections and recurring false positives so they can be tuned out.

What We Are Looking For

Required

  • 1+ year in IT support, service desk, systems administration, or a security operations role. Strong candidates with certifications and demonstrable lab work will be considered without commercial security experience.
  • Working knowledge of Microsoft 365 and a cloud-first or hybrid environment.
  • Networking and mail flow fundamentals: TCP/IP, DNS, SMTP, MX records, VPN, firewall concepts.
  • Windows and macOS fundamentals - processes, logons, and where the logs live.
  • Understanding of common attack techniques: phishing, credential theft, MFA fatigue, token theft, malware delivery.
  • Professional written and verbal English. Case notes and escalations are written in English.
  • The discipline to follow a runbook exactly, and the judgement to escalate early rather than improvise.

Preffered

  • Hands-on exposure to Microsoft Sentinel, Defender XDR, Defender for Office 365, or Entra ID.
  • Ability to read and adapt a KQL query, or basic PowerShell.
  • CompTIA Security+ or Microsoft SC-900.
  • Familiarity with MITRE ATT&CK.
  • Awareness of NIST SP 800-171, CMMC 2.0, or GDPR.

What KVG Offers

  • Funded Microsoft certification path - SC-200 is the target credential for this role, with the exam paid by KVG.
  • A defined progression route from L1 triage to L2 analysis.
  • A single-vendor Microsoft security stack: Sentinel, Defender XDR, Entra ID, Intune, Purview - depth rather than tool sprawl.
  • Direct mentoring from the Cloud Security Engineer rather than an anonymous alert queue.
  • European business-hours coverage with rotational extended-hours support for other regions. This is not a 24/7 shift rotation.

Professional Competencies

Collaborative Spirit | Results Above All | Innovation as a Habit | Creative Freedom | Financial Prudence | Eternal Learner | Daring Adventures | Open Feedback | Integrity in Action | Embrace Change | Accountability

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

SOC Analyst Related jobs

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.