Duke ngarkuar...

Security Operations Center Analyst

Arpya

/job-details/11305

Tirana
full_time
Publikuar Sot
Arpya · Tirana, Albania · On-site · Full-time · 24/7 shift rota

**About Arpya**

Arpya is the cybersecurity and AI division of Global Technologies Italia, delivering offensive security, defensive security (SOC/MDR) and GRC services to regulated EU mid-market clients. Our 24/7 Security Operations Centre (SOC) in Tirana is hiring L1 and L2 analysts.

**The role**

You monitor, triage and investigate security events across multiple client environments (endpoints, identities, email, cloud, network) and escalate or contain according to agreed runbooks and SLAs. You report to the SOC Lead.

**What you will do**

L1

- Monitor SIEM and EDR/XDR alert queues; perform first-line triage and severity classification
- Enrich alerts with asset, identity and threat-intelligence context; escalate true positives to L2 within SLA
- Execute runbooks and approved containment actions
- Document every case in the ticketing system and complete structured shift handovers

L2

- Investigate escalated incidents end to end: scoping, root cause, containment, recovery recommendations
- Hunt for threats across endpoint, identity and cloud logs, mapped to MITRE ATT&CK
- Tune detection rules and build new use cases in SIEM/EDR; reduce false positives
- Write and maintain runbooks; mentor L1 analysts
- Produce incident reports and contribute to client service reviews

**What we need**

Both levels

- Strong fundamentals: TCP/IP, Windows and Linux, Active Directory, common attack techniques
- Good written and spoken English
- Availability for a 24/7 rota including nights, weekends and public holidays
- Based in, or willing to relocate to Tirana

L1

- 0 to 2 years in a SOC, NOC, IT support or security role; strong graduates considered
- Familiarity with at least one SIEM or EDR platform

L2

- 2+ years hands-on SOC or incident response experience
- Query languages such as KQL or SPL; log analysis at scale
- EDR/XDR administration and detection engineering experience
- Incident handling under SLAs in a multi-client (MSSP) setting is a strong plus

**Nice to have**

- Certifications: CompTIA Security+, BTL1, GCIH, GCIA, GCTI, Microsoft SC-200
- Scripting: Python, PowerShell or Bash
- Italian language

**What we offer**

- Hands-on work across multiple clients, not a single environment
- Direct involvement in detection engineering and runbook development
- Clear career path from L1 to L2 and L3
- Exposure to EU regulated environments (ISO 27001, NIS2, DORA)