Job Description

How you will work

You will work directly with the people who design, operate and depend on the systems being protected. Recommendations must identify the threat, the affected asset and a realistic implementation path. The partner values careful evidence, proportionate controls and clear escalation when risk cannot be removed immediately.

You will work with experienced colleagues who review both the outcome and the reasoning behind it. The partner expects curiosity, care and steady growth rather than instant expertise. You will receive real responsibility in controlled steps and clear opportunities to build evidence of your capability.

What you will do

  • Monitor and triage security alerts.
  • Investigate endpoint, identity, network and cloud events.
  • Document evidence, decisions and escalation clearly.
  • Support incident containment and recovery activities.
  • Tune detections using lessons from false positives and incidents.
  • Maintain playbooks and contribute to threat hunting exercises.

What you will bring

  • Education, certification or early experience in cybersecurity or IT operations.
  • Understanding of networks, Windows, Linux and identity basics.
  • Ability to analyse logs and form a testable hypothesis.
  • Careful written communication and shift handover habits.
  • Professional English and willingness to learn from review.
  • Integrity when handling sensitive information.

Experience that would add value

  • SIEM or EDR laboratory experience.
  • Scripting in Python or PowerShell.
  • Internship in a SOC, service desk or infrastructure team.

A background that can succeed here

You may be a recent graduate, system administrator, support technician or self taught security practitioner with credible projects. We value curiosity backed by method and the ability to say what the evidence does not yet show.

What makes the opportunity interesting

The partner offers structured exposure to modern security tooling and senior colleagues who will review your reasoning. The role can grow toward detection engineering, incident response or cloud security.

The exact partner, employment model, compensation, start date and working arrangement will be explained openly during the process. Nordic Investin will make sure you understand the context, expectations and decision path before you are asked to commit significant time.

The recruitment conversation

During the process, Nordic Investin will focus on concrete decisions you have made: the context you received, the alternatives you considered, the result you observed and what you would change today. You do not need every optional technology if your core experience transfers and you can explain how you would close the gap.

Apply now
Report job

More job openings