Who We Are
At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward - always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers and our communities.
The Role
• Work in 8X5 model, as part of Global SOC Team that operates in office time with possible on-call (8:00 - 17:00)
• Conduct preliminary incident triage according to the Security Incident Management Triage Matrix and set the priority, provide analysis, determine, track remediation, and escalate as appropriate.
• Utilize the intrusion detection, security scanning, security log collection, content filtering, and other security related systems to perform triage and investigation and incident response.
Want more jobs like this?
Get jobs delivered to your inbox every week.
• Lead investigations and conduct deep analysis of security events focused on rapid containment, remediation, and mitigation.
• Lead in the detection, triage, analysis and response to cyber-attacks.
• Provide insight and expertise to examine malicious code (malware), attack vectors, network communication methods, analyze threats against target systems and networks, determine target network capabilities and vulnerabilities.
• Training and mentoring Level 1 peers to improve SOC Analyst capability.
• Assist in containing and mitigating security incidents to prevent further damage.
• Collaborate with Level 3 analysts, incident response teams, and other stakeholders to develop and execute incident response plans.
• Ensure the SOC team documentation is up to date, including investigation Playbooks, as well incidents have current notes related to investigation steps which were performed.
• Cooperation with other Security Analysts and different teams, including Threat Hunting, Threat Intelligence, Red Team, Perimeter Protection in order to improve the SOC monitoring and defense capabilities.
• Categorization and prioritization of security incidents
• Looking for the correlation between various security events
What we can offer:
- Competitive salary and benefits: Private Life & Health Insurance, Voluntary Pension Fund contribution and monthly benefit allowance to SZÉP card.
- Internal rewards and recognition programs.
- Ongoing wellbeing initiatives (including mental health support), team outings and seasonal gifts.
- Commuting and relocation support for local, EU or overseas candidates and their spouses and children (provided certain conditions are met).
- Annual profit-sharing bonus subject to company performance.
- Personal and professional development both in-person and online (certified trainings, on-the-job coaching & mentoring, career progression support); we also nurture new talent and 'career changers' through our comprehensive education programs and exclusive accreditations.
- Flexible working opportunities (part-time and home office) for a better work-life balance.
- Annual 1-day paid leave for volunteering.
- An open, diverse, inclusive, and empathetic culture that supports learning and encourages collaboration over competition.
- As the proud owner of the Family Friendly Workplace certification, we provide great benefits for working parents with fair maternity and paternity leave policies such as additional bonding leave for dads and same-sex domestic partners at the birth or adoption of a child, accommodating working parents based on needs, organizing family events and many more.
Your Future at Kyndryl
When you join Kyndryl, you're not just joining a company - you're entering a space of opportunities. Our partnerships with industry alliances and vendors mean you'll have access to skilling and certification programs needed to excel in Security & Resiliency, while simultaneously supporting your personal growth. Whether you envision your career path as a technical leader within cybersecurity or transition into other technical, consulting, or go-to-market roles - we're invested in your journey.
Who You Are
You're good at what you do and possess the required experience to prove it. However, equally as important - you have a growth mindset; keen to drive your own personal and professional development. You are customer-focused - someone who prioritizes customer success in their work. And finally, you're open and borderless - naturally inclusive in how you work with others.
Who You Are
Required Technical and Professional Expertise
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or other related fields, from an accredited university. Equivalent professional experience can be used in lieu of a degree.
- 2-5 years of security analyst experience, preferably in a managed services environment.
- Proven experience with operations using commonly used information security solutions (with main focus on MS Sentinel, MS Defender)
- Proven technology knowledge of Windows, Active Directory, Linux, SIEM Solutions, Antivirus software, Proxy.
- Experience in Cloud Security monitoring and in advanced analytics (UEBA)
- Knowledge of the most common and used frameworks (E.g., NIST CSF, ISO2700x, CMM SOC, etc.)
- Sound experience on programming languages: Python and/or R. and/or PowerShell, KQL
- Proven knowledge of current security threats, techniques, and landscape, and a dedicated and self-driven desire to research and learn more about the information security landscape.
- Review and triage experience with endpoint detection and response, SIEM tools
- Experience and knowledge related to the configuration and maintenance of security monitoring and reporting platforms, such as correlation engineering.
- Strong analytical skills, decision making, being able to work under time pressure, cooperating with other people and using the escalation processes when necessary.
- Experience in technical Team coordination/management would be a plus.
- English: Fluent (German would be a plus)
- Strong critical thinking and analytical skills and ability to think "out of the box" required.
- Must be able to work independently or with a team, under minimum supervision.
Preferred Technical and Professional Experience
- MBA or master's degree
- CompTIA Security+, GIAC Security Essentials Certification (GSEC), SIEM & EDR Foundation certificates (Such as Microsoft Sentinel and Defender).
- Microsoft, Splunk, SANS.org security certifications related to SIEM, EDR products and operations (in example Microsoft AZ-500)
- A minimum of 2 years hands on experience with one or more of the following areas:
- Operation and Implementation of SIEM and EDR solutions including:
- QRadar or Splunk and Microsoft Sentinel, MS Defender.
- Desing and Implementation of Monitoring strategy including:
- Thorough knowledge on defining data sources monitoring based on clients' business
- Knowledge on MITRE Frameworks (ATT&CK, D3FEND)
- Familiar with Cyber Kill Chain
- Desing and Implementation of Configuration Governance solutions including:
- Knowledge on how to operationalize ongoing security configuration governance service using SOC standard methodologies, metrics, Operational Procedures.
- Operation and Implementation of SIEM and EDR solutions including:
- Familiarity with threat intelligence feeds and how to incorporate them into analysis.
- Knowledge of threat actor groups, tactics, techniques, and procedures (TTPs).
Being You
Diversity is a whole lot more than what we look like or where we come from, it's how we think and who we are. We welcome people of all cultures, backgrounds, and experiences. But we're not doing it single-handily: Our Kyndryl Inclusion Networks are only one of many ways we create a workplace where all Kyndryls can find and provide support and advice. This dedication to welcoming everyone into our company means that Kyndryl gives you - and everyone next to you - the ability to bring your whole self to work, individually and collectively, and support the activation of our equitable culture. That's the Kyndryl Way.
What You Can Expect
With state-of-the-art resources and Fortune 100 clients, every day is an opportunity to innovate, build new capabilities, new relationships, new processes, and new value. Kyndryl cares about your well-being and prides itself on offering benefits that give you choice, reflect the diversity of our employees and support you and your family through the moments that matter - wherever you are in your life journey. Our employee learning programs give you access to the best learning in the industry to receive certifications, including Microsoft, Google, Amazon, Skillsoft, and many more. Through our company-wide volunteering and giving platform, you can donate, start fundraisers, volunteer, and search over 2 million non-profit organizations. At Kyndryl, we invest heavily in you, we want you to succeed so that together, we will all succeed.
Get Referred!
If you know someone that works at Kyndryl, when asked 'How Did You Hear About Us' during the application process, select 'Employee Referral' and enter your contact's Kyndryl email address.