
Senior Security Analyst (L2/L3)
Skills & requirements
About the role
Senior Security Analyst (L2/L3)
About the role
Quadcode is looking for a Senior Security Analyst to join its Security team in Cyprus.
This role focuses on security monitoring, threat detection, incident investigation, and response across cloud, infrastructure, operating-system, and remote-user environments.
You will work closely with infrastructure, operations, NOC, compliance, and other security stakeholders to investigate suspicious activity, improve detection capabilities, and coordinate remediation when security issues are identified.
The role combines hands-on incident response with detection engineering, automation, vulnerability management, and continuous improvement of security operations.
What you’ll be doing
Monitor and analyse security events across multiple environments.
Investigate suspicious activity and potential security incidents.
Participate in and lead incident-response activities.
Develop and improve security-event correlation rules.
Build and maintain incident-response playbooks.
Automate repetitive incident-response and security-analysis workflows.
Develop detection logic for suspicious or malicious behaviour.
Test detection rules through attack emulation and controlled security exercises.
Collect, analyse, and correlate indicators of compromise from multiple systems.
Investigate incidents across distributed infrastructure and remote-user environments.
Coordinate vulnerability remediation with relevant engineering and infrastructure teams.
Review vulnerabilities and help prioritise remediation based on security risk.
Conduct regular incident-response simulations and exercises.
Research new security technologies and analytical approaches.
Improve security tooling and detection processes.
Define security requirements for operating systems, infrastructure, networks, and services.
Support secure configuration standards related to incident detection and response.
Participate in security and compliance audits.
Work with other technical and business teams to communicate security findings and coordinate response actions.
What we’re looking for
At least three years of professional experience as a Security Analyst or in a similar security-operations role.
Practical experience handling L2-level security incidents.
Strong incident investigation and response skills.
Experience developing security automation using Python.
Experience investigating incidents in distributed infrastructure environments.
Experience investigating security issues affecting remote employees.
Practical experience collecting and analysing indicators of compromise.
Experience developing SIEM correlation rules.
Experience validating detection rules using attack-emulation techniques.
Strong understanding of security controls in modern operating systems.
Knowledge of common attacks against networks, infrastructure, web applications, and cloud environments.
Hands-on experience using Splunk or another SIEM platform.
Willingness to develop strong Splunk expertise if coming from another SIEM environment.
Experience analysing network traffic.
Practical knowledge of the MITRE ATT&CK framework.
Strong analytical and technical problem-solving abilities.
The ability to communicate security findings clearly to technical and non-technical teams.
Russian proficiency at approximately C1 level.
English proficiency at approximately B1/B2 level.
Skills that would be an advantage
Previous experience in fintech or financial services.
Hands-on experience using endpoint detection and response platforms.
Familiarity with SentinelOne.
Experience analysing and managing vulnerabilities.
Practical use of AI tools for security investigation or automation.
Experience writing regular expressions.
SQL knowledge.
Experience working with relational databases.
Familiarity with ELK-based security analytics.
Experience using Loki.
Experience with analytical platforms such as Greenplum or ClickHouse.
Experience supporting PCI DSS audits.
Familiarity with DORA-related security or compliance requirements.
Experience working with open-source security analytics platforms.
Technology environment
The security team works across a modern hybrid infrastructure and security stack that includes:
Splunk
Check Point
Rapid7
AWS
OpenStack
GitLab
Kubernetes
Infrastructure as Code
Python
Linux
Windows
macOS
The environment also includes cloud and hybrid infrastructure, with opportunities to apply AI tooling to real security operations.
Work arrangement
This is a full-time hybrid position based in Cyprus.
Available office locations include:
Limassol
Larnaca
Standard working hours are during normal business hours.
Paid overtime may be required when significant security incidents occur outside normal working hours.
Benefits
Benefits offered for this position include:
Hybrid working arrangement.
13th salary.
21 days of annual leave.
Private health insurance.
Mental-health support services.
Up to three sick days per quarter without a medical certificate.
Catered office lunches.
Education reimbursement for eligible kindergarten or school expenses.
Access to an onsite gym.
Corporate events and workshops.
Bonuses for selected personal and family milestones.
Birthday and work-anniversary gifts.
Company-provided laptop.
Required tooling for security incident handling.
Corporate subscriptions to AI platforms such as Claude, Gemini, and GPT.
Access to an employee rewards marketplace.
Language-learning opportunities through the company’s internal rewards programme.
The complete benefits package and eligibility conditions should be confirmed directly with Quadcode during the recruitment process.
About Quadcode
Quadcode is a fintech company developing financial technology and brokerage products for international markets.
Its technology environment includes an internal trading platform that is also provided to other brokers as a Software-as-a-Service solution.
The Security team is responsible for monitoring, detecting, investigating, and responding to threats across the company’s infrastructure, cloud platforms, systems, and services.
How to apply
Applicants should submit an up-to-date CV through Quadcode’s official careers page.
Your application should clearly demonstrate:
Your total security-operations experience.
Incident-response cases you have investigated or led.
Your experience with Splunk or another SIEM platform.
Correlation and detection rules you have developed.
Your experience using Python for security automation.
Attack-emulation or detection-validation work you have performed.
Your experience with MITRE ATT&CK.
Network-traffic investigations you have completed.
Experience collecting and analysing indicators of compromise.
Vulnerability-management or remediation work you have supported.
Any experience with SentinelOne, Rapid7, AWS, Kubernetes, or cloud security.
Your involvement in PCI DSS, DORA, or other compliance audits.
Any AI tools you have used to improve security operations.
Applications are processed directly by Quadcode. cyprustech.careers is presenting this vacancy for informational purposes and is not acting as the employer or recruitment agency for this position.