Leevi Auvinen joined Netox as a SOC Analyst in spring 2026. Before Netox, he had worked in cybersecurity SOC roles for more than three years, but moving into a new role brought with it a new environment, several customer accounts and a lot to learn.
Leevi first came across Netox at the Disobey event, where he met his current supervisor and had the chance to talk with other people from Netox as well. Although he had not been familiar with the company before, the first impression stayed with him.
“I spoke with several people from Netox and asked them what kind of workplace it was. The answers were very open, and many said they had really enjoyed working there,” Leevi says.
The impression was strengthened by the fact that many of them had already worked at Netox for a long time. For Leevi, this said a lot about the work community: people do not just pass through, but feel good enough to stay.
Guarding information security in customer environments
As a SOC Analyst, Leevi monitors customers’ systems and investigates security anomalies in their environments. He describes the role as guarding information security.
“We monitor what happens in companies’ systems. For example, if a user downloads one hundred gigabytes of data from OneDrive, we investigate whether that is normal behaviour for that user or whether something unusual is going on,” Leevi says.
In practice, the work is about continuously interpreting observations. An anomaly may be caused by a completely ordinary work task, but it may also be a sign of malicious activity. That is why a SOC Analyst needs to understand both technology and the customer’s environment.
In his previous role, Leevi monitored the environment of a single organisation. At Netox, there are several customer environments to monitor, which makes the work more varied.
“The basic work is the same, but now there are more customer environments. It requires flexibility and the willingness to learn and understand what is happening in different environments.”
Leevi’s work is structured around 12-hour monitoring shifts. Four working days are followed by a recovery period, and thanks to the rotation, customers’ environments are monitored around the clock.
The hardest part is also the most rewarding
In cybersecurity, nothing stays still for very long. New tools, technologies and AI models are constantly emerging, and security threats are changing at the same time. According to Leevi, the work requires accepting that you can never know everything in advance.
“This is not a profession where you graduate from school and then know everything. It takes self-discipline, initiative and a willingness to keep studying,” Leevi says.
That same thing is also what makes the work interesting. When a topic sparks his interest, he can dive deeper into it and see his own development reflected in everyday work.
His interest in cybersecurity also shows in his free time. At work, Leevi focuses on defensive cybersecurity, but outside work he practises the offensive side, for example on training platforms designed for ethical hacking.
“It also helps you understand the other side. When you know how an attacker might think, you can look at defensive work from a slightly different perspective.”
Netox also supports competence development in practical ways, for example by encouraging employees to complete IT certifications and supporting them financially.
Teamwork shows in everyday actions
During his first months, Leevi has noticed that help is easy to ask for at Netox. In a new organisation, questions inevitably come up, and the right person to answer them is not always found on the first try. That has not been a problem.
“I have already asked some silly questions, and sometimes I have asked the wrong people too. If someone does not know the answer, they point me towards the right person. People are happy to help,” Leevi says.
For Leevi, this has also changed how he sees teamwork. In the past, talk about working as one team could easily sound like something said in organisational speeches. At Netox, it has shown in practice.
“Here, it is not just PR talk. If someone does not know the answer, they help you forward. And when the right person is found, they help with the issue.”





