Posted on: 23/06/2026
About the Role :
We are seeking a highly skilled Senior SOC Analyst to join our cybersecurity team and support 24/7 security operations in partnership with an MDR provider.
This role focuses on hands-on threat monitoring, incident response, and detection engineering across a modern Microsoft security ecosystem.
You will play a critical role in identifying, analyzing, and responding to cyber threats, while continuously improving detection capabilities and reducing response times.
Key Responsibilities :
- Monitor, triage, and investigate security alerts across Microsoft Sentinel and Defender XDR environments.
- Perform incident response activities including containment, eradication, and recovery.
- Collaborate with MDR provider (e.g., Expel) for alert escalation, validation, and resolution.
- Analyze alerts from Microsoft Defender (Endpoint, Identity, Cloud Apps, Office 365).
- Investigate and respond to alerts from Zscaler (ZIA/ZPA) and Proofpoint email security.
- Develop and tune KQL queries, analytics rules, and detection logic in Microsoft Sentinel.
- Execute and improve SOAR playbooks and automation workflows.
- Perform root cause analysis and post-incident reviews.
- Reduce false positives and improve signal-to-noise ratio across tools.
- Leverage frameworks such as MITRE ATT&CK for threat analysis and mapping.
- Contribute to the development and maintenance of incident response playbooks and runbooks.
- Track and support improvement of key SOC metrics such as MTTD, MTTR, and alert quality.
- Produce detailed incident reports and communicate findings to stakeholders.
- Stay updated on emerging threats, vulnerabilities, and attack techniques.
Required Skills & Experience :
- 7-9 years of experience in Security Operations / SOC / Incident Response.
- Strong hands-on experience with :
1. Microsoft Sentinel (SIEM).
2. Microsoft Defender XDR.
3. Proficiency in KQL (Kusto Query Language) for detection and investigation.
4. Experience working with an MDR provider (preferred but not mandatory).
- Knowledge of :
1. Zscaler (ZIA/ZPA).
2. Proofpoint email security.
- Strong understanding of :
1. Incident response lifecycle.
2. Threat detection & analysis.
3. Log analysis and correlation.
4. Familiarity with MITRE ATT&CK framework.
5. Experience with SOAR and automation workflows.
- Strong analytical and problem-solving skills.
- Certifications preferred :
1. SC-200 (Microsoft Security Operations Analyst).
2. GCIH / CISSP (or equivalent).
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1647579