Vacancy
Security Operations Analyst (Tier 2)
Tallinn, Estonia · Information Security & IT · Permanent, full-time
About the team
Terravek's Security Operations Centre in Tallinn covers the corporate estate, ORBIS Cloud and the ground segment. We run 24/7 with a follow-the-sun handover and we do not believe in alert fatigue as a cost of doing business.
What you will do
- Triage and investigate escalated alerts from the Tier 1 queue
- Write and tune detection content in Microsoft Sentinel
- Lead containment on medium-severity incidents and support the IR lead on major ones
- Contribute to the runbook library and the quarterly purple team exercises
- Support the coordinated vulnerability disclosure triage queue
What we are looking for
- Three or more years in a SOC or incident response function
- Fluent with KQL or an equivalent query language
- Able to explain an investigation clearly in writing
- Working English; Estonian or Russian useful but not required
Skills and technologies
These are the things we cannot train quickly. Everything else we can.
- SIEM (Microsoft Sentinel)
- KQL
- EDR triage
- MITRE ATT&CK
- Incident response
- Windows and Linux internals
Useful, not required
- GIAC or equivalent certification
- Detection engineering
- Threat intelligence
- Python for automation
What we offer
- 28 days annual leave
- Private health insurance
- Hybrid working, 2 office days a week
- €1,500 annual learning budget
- Sports compensation €400/year
- Employee share participation plan after 12 months
Apply
Send a CV and a short covering note — a few paragraphs, not a form letter — to careers@terravek.com, quoting reference TVK-2026-043.
Questions about the role itself can go directly to the hiring manager, Riina Tamm, at riina.tamm@terravek.com. We would rather you asked.