Customer portal System status Developers Contact Search
Vacancy

Security Operations Analyst (Tier 2)

Tallinn, Estonia · Information Security & IT · Permanent, full-time

About the team

Terravek's Security Operations Centre in Tallinn covers the corporate estate, ORBIS Cloud and the ground segment. We run 24/7 with a follow-the-sun handover and we do not believe in alert fatigue as a cost of doing business.

What you will do

  • Triage and investigate escalated alerts from the Tier 1 queue
  • Write and tune detection content in Microsoft Sentinel
  • Lead containment on medium-severity incidents and support the IR lead on major ones
  • Contribute to the runbook library and the quarterly purple team exercises
  • Support the coordinated vulnerability disclosure triage queue

What we are looking for

  • Three or more years in a SOC or incident response function
  • Fluent with KQL or an equivalent query language
  • Able to explain an investigation clearly in writing
  • Working English; Estonian or Russian useful but not required

Skills and technologies

These are the things we cannot train quickly. Everything else we can.

  • SIEM (Microsoft Sentinel)
  • KQL
  • EDR triage
  • MITRE ATT&CK
  • Incident response
  • Windows and Linux internals

Useful, not required

  • GIAC or equivalent certification
  • Detection engineering
  • Threat intelligence
  • Python for automation

What we offer

  • 28 days annual leave
  • Private health insurance
  • Hybrid working, 2 office days a week
  • €1,500 annual learning budget
  • Sports compensation €400/year
  • Employee share participation plan after 12 months

Full benefits by country

Apply

Send a CV and a short covering note — a few paragraphs, not a form letter — to careers@terravek.com, quoting reference TVK-2026-043.

Questions about the role itself can go directly to the hiring manager, Riina Tamm, at riina.tamm@terravek.com. We would rather you asked.