Strength. Care. Growth
You’ll know A1 Bulgaria is the right place for you if you are driven by:
- Opportunities to learn and build your career.
- Meaningful work in a stable and fast-paced company.
- Diversity of people, projects, and platforms.
- A supportive, fun, and inspiring place to work.
Your daily routine would include:
- Monitoring customer environments for security threats, suspicious activities, and policy violations.
- Analyzing and triaging security alerts generated by SIEM, EDR/XDR, network, cloud, and other security technologies.
- Investigating security incidents and determining their severity, impact, and business relevance.
- Distinguishing between true positive and false positive alerts and taking appropriate actions.
- Escalating validated incidents to customer security teams according to agreed procedures and SLAs.
- Communicating incident details, recommendations, and investigation results to customers in a clear and professional manner.
- Correlating information from multiple data sources to identify malicious activity and emerging threats.
- Supporting incident response activities and providing investigative assistance when required.
- Documenting investigations, findings, and response actions within ticketing and case management systems.
- Contributing to threat hunting, detection improvements, use case development, and SOC process optimization.
- Collaborating with international colleagues, customers, and technology partners to improve overall security posture.
We’ll know you can make it if you have:
- Experience in a Security Operations Center, Managed Security Services, Incident Response, or related cybersecurity role.
- Understanding of cybersecurity threats, attack techniques, and incident handling processes.
- Experience working with SIEM platforms such as Splunk, Microsoft Sentinel, QRadar, or similar technologies.
- Familiarity with EDR/XDR solutions, Microsoft Defender, network security monitoring, and cloud security services.
- Strong investigative and analytical skills with the ability to assess and prioritize security events.
- Experience working in a customer-oriented environment and communicating technical findings to different audiences.
- Ability to work efficiently under pressure and manage multiple incidents simultaneously.
- German language proficiency at C1 level or native speaker(mandatory).
- Strong English communication skills.
Apply now!