About this role
About The Role
KVG is looking for an L1 SOC Analyst to become the first line of security monitoring for a Microsoft-based environment spanning Moldova, Romania, Ukraine, Germany, Spain, the Philippines, and the United States. You will own the daily triage of alerts in Microsoft Sentinel and Microsoft Defender XDR, and the review of the Microsoft 365 email quarantine - deciding what is real, what is noise, and what needs to go up the chain.
This is a structured entry point into security operations. You will work to documented runbooks and a clear action mandate, alongside our Cloud Security Engineer, in an environment with genuine compliance weight behind it (NIST SP 800-171 and CMMC 2.0). We fund your certification path and expect you to grow into L2 analysis.
What You Will Do
- Monitor and triage incidents in Microsoft Sentinel and Microsoft Defender XDR, working in order of severity.
- Decide whether an alert is a true positive, a false positive, or benign - and write down why.
- Review the Defender for Office 365 quarantine, handle user-reported phishing, and action release or block decisions.
- Analyse message headers, SPF/DKIM/DMARC results, URLs, and attachments to reach a defensible verdict.
- Run pre-built KQL queries in Advanced Hunting to work out who and what was affected.
- Apply runbook-defined containment: revoke sessions, block sign-in, isolate a device, purge a delivered message.
- Escalate anything beyond your mandate with a clear timeline, the evidence, and what you already did.
- Keep case records that hold up under audit, and hand over cleanly at the end of each shift.
- Flag noisy detections and recurring false positives so they can be tuned out.
What We Are Looking For
Required
- 1+ year in IT support, service desk, systems administration, or a security operations role. Strong candidates with certifications and demonstrable lab work will be considered without commercial security experience.
- Working knowledge of Microsoft 365 and a cloud-first or hybrid environment.
- Networking and mail flow fundamentals: TCP/IP, DNS, SMTP, MX records, VPN, firewall concepts.
- Windows and macOS fundamentals - processes, logons, and where the logs live.
- Understanding of common attack techniques: phishing, credential theft, MFA fatigue, token theft, malware delivery.
- Professional written and verbal English. Case notes and escalations are written in English.
- The discipline to follow a runbook exactly, and the judgement to escalate early rather than improvise.
Preffered
- Hands-on exposure to Microsoft Sentinel, Defender XDR, Defender for Office 365, or Entra ID.
- Ability to read and adapt a KQL query, or basic PowerShell.
- CompTIA Security+ or Microsoft SC-900.
- Familiarity with MITRE ATT&CK.
- Awareness of NIST SP 800-171, CMMC 2.0, or GDPR.
What KVG Offers
- Funded Microsoft certification path - SC-200 is the target credential for this role, with the exam paid by KVG.
- A defined progression route from L1 triage to L2 analysis.
- A single-vendor Microsoft security stack: Sentinel, Defender XDR, Entra ID, Intune, Purview - depth rather than tool sprawl.
- Direct mentoring from the Cloud Security Engineer rather than an anonymous alert queue.
- European business-hours coverage with rotational extended-hours support for other regions. This is not a 24/7 shift rotation.
Professional Competencies
Collaborative Spirit | Results Above All | Innovation as a Habit | Creative Freedom | Financial Prudence | Eternal Learner | Daring Adventures | Open Feedback | Integrity in Action | Embrace Change | Accountability