Job Description, Responsibilities & Requirements
About the Position
JOIN OUR TEAM
At Levi Nine we are passionate about what we do. We love our work and together in a team we are smarter and stronger. We work in a dynamic and challenging environment with talented and forward-thinking people who are part of creative and innovative teams. We are looking for skilled team players who make change happen. Are you one of these players?
OUR PARTNER:
Our partner, ABN AMRO Clearing, is a global leader in the domain of clearing, offering access to a wide range of listed instruments on markets across the globe.
IT is at the heart of their organization with more than 30 different product teams and 10 different platform teams that are trying to build the best products & services for their customers.
Their presence in important financial centers like Amsterdam, Chicago, Sydney, Singapore, Tokyo Hong Kong, London, Sao Paulo, Frankfurt and Iasi, allows them to effectively serve clients worldwide and maintain close proximity to their diverse customer base.
THE ROLE INVOLVES:
As a SOC Analyst (L2), you focus on detection engineering and incident investigation, working hands-on with Splunk Enterprise Security.
You contribute to a SOC in a build-up phase, helping shape detection engineering practices, playbooks, and processes.
Detection engineering is your primary focus, while investigations help continuously improve detection quality.
You will also contribute to the adoption of Detection as Code (DaC) practices, where detections are treated as structured, version-controlled, and reusable assets.
You work closely with the Senior L3 Detection Lead to implement detection use cases, improve coverage, and contribute to a structured detection engineering lifecycle.
Responsibilities
- Investigate alerts escalated from L1 analysts.
- Build and improve detection use cases in Splunk ES.
- Tune alerts to improve quality and reduce false positives.
- Develop and maintain detection & response playbooks.
- Apply Detection as Code principles.
- Contribute to version-controlled detection content.
- Identify detection gaps and propose improvements.
- Support threat hunting activities and translate findings into detections.
- Collaborate with L3 to refine detection logic and standards.
Requirements
- 3-5 years in SOC / incident response / blue team roles
- Hands-on experience with SIEM (preferably Splunk ES)
- Experience handling Tier 2 investigations
- Strong understanding of detection engineering and use case development
- Familiarity with MITRE ATT&CK framework
- Ability to analyze logs across endpoint, network, and cloud environments
- Comfortable working in a build-up environment, where processes and standards are still being established.
Nice to Have
- Certifications such as the following would be desirable but not mandatory: GCIH, GDAT, GCDA, GISP, OSDA, CCFR, SC-900, SC-200, Splunk
- Basic automation/scripting experience
- Interest in detection engineering frameworks and best practices
- A keen interest in cyber security and a desire to learn more and improve the current way of working
- Relevant university degree in Computer Science, Engineering, or a related field
Soft Skills
- Fluent English, with good written and verbal communication skills
- Strong analytical and investigative mindset
- Ability to work under pressure
- Clear communication and structured documentation
- Proactive and improvement-driven approach
We Offer
- Location: Iași, RO
- Remote status: Hybrid
About the Company
Levi9 is a nearshore technology service provider with around 1000 employees and 50+ customers. We specialize in custom made business IT – 95% of our work is on the revenue side of our customers. This is where time to market, high productivity, stable team velocity, and great quality through automation, agility, intensive interaction and understanding matter most.