Job Title: Junior SOC Analyst /Senior SOC Analyst
Location:
Role Purpose
Execute advanced security monitoring, threat detection, incident response, and proactive threat hunting across Microsoft Sentinel, Defender XDR, SOAR, and EDR platforms within a managed SOC environment.
Core Responsibilities
- Monitor alerts generated by Microsoft Sentinel and Defender platforms.
- Investigate alerts, validate malicious activity, and escalate or remediate per defined playbooks.
- Respond to cyber events including phishing, malware, credential abuse, lateral movement, cloud attacks, identity threats, and endpoint intrusions.
- Conduct hypothesis-based and intel-driven hunts using KQL, UEBA, IOC feeds, TI enrichment, and Defender telemetry.
- Execute automated and semi-automated workflows; provide feedback for logic improvements.
- Determine severity, containment strategies, and response paths following MITRE ATT&CK and NIST IR lifecycle frameworks.
- Maintain accurate case records, timelines, evidence, analyst notes, and RCA documentation in SOC platforms (ServiceNow/Jira/Sentinel Cases).
- Recommend improvements for tuning alerts, refining rules, reducing false positives/negatives, and enhancing watchlists.
- Create customer-facing IR summaries detailing severity, impact, timeline, outcome, and lessons learned.
- Operate within SLA/OLA targets and ensure compliance with security frameworks and customer policy requirements.
Required Technical Skills
- Cybersecurity Experience: 2–7+ years
- SOC Experience: 4+ years
- Hands-on Microsoft Security Stack experience
- Microsoft Sentinel SIEM Operations
- KQL Querying and Log Analysis
- Microsoft Defender XDR (Identity, Endpoint, Email, Cloud Apps)
- Security Incident Response & Forensics
- SOAR (Logic Apps awareness, runbook execution)
- Cloud Security (Azure, Entra ID)
- Threat Intelligence & MITRE ATT&CK Mapping
- Network, Host, and Identity Security Fundamentals
- Experience with EDR platforms (Defender, CrowdStrike, SentinelOne)
Preferred Certifications
- Microsoft SC-200, AZ-500
- Cybersecurity: CEH, Security+, CySA+, GCIA, GCIH
- Value Add: SC-300, SC-100