HamburgerMenu
hirist

Job Description

About the Role :

We are seeking a highly skilled Senior SOC Analyst to join our cybersecurity team and support 24/7 security operations in partnership with an MDR provider.

This role focuses on hands-on threat monitoring, incident response, and detection engineering across a modern Microsoft security ecosystem.

You will play a critical role in identifying, analyzing, and responding to cyber threats, while continuously improving detection capabilities and reducing response times.

Key Responsibilities :

- Monitor, triage, and investigate security alerts across Microsoft Sentinel and Defender XDR environments.

- Perform incident response activities including containment, eradication, and recovery.

- Collaborate with MDR provider (e.g., Expel) for alert escalation, validation, and resolution.

- Analyze alerts from Microsoft Defender (Endpoint, Identity, Cloud Apps, Office 365).

- Investigate and respond to alerts from Zscaler (ZIA/ZPA) and Proofpoint email security.

- Develop and tune KQL queries, analytics rules, and detection logic in Microsoft Sentinel.

- Execute and improve SOAR playbooks and automation workflows.

- Perform root cause analysis and post-incident reviews.

- Reduce false positives and improve signal-to-noise ratio across tools.

- Leverage frameworks such as MITRE ATT&CK for threat analysis and mapping.

- Contribute to the development and maintenance of incident response playbooks and runbooks.

- Track and support improvement of key SOC metrics such as MTTD, MTTR, and alert quality.

- Produce detailed incident reports and communicate findings to stakeholders.

- Stay updated on emerging threats, vulnerabilities, and attack techniques.

Required Skills & Experience :

- 7-9 years of experience in Security Operations / SOC / Incident Response.

- Strong hands-on experience with :

1. Microsoft Sentinel (SIEM).

2. Microsoft Defender XDR.

3. Proficiency in KQL (Kusto Query Language) for detection and investigation.

4. Experience working with an MDR provider (preferred but not mandatory).

- Knowledge of :

1. Zscaler (ZIA/ZPA).

2. Proofpoint email security.

- Strong understanding of :

1. Incident response lifecycle.

2. Threat detection & analysis.

3. Log analysis and correlation.

4. Familiarity with MITRE ATT&CK framework.

5. Experience with SOAR and automation workflows.

- Strong analytical and problem-solving skills.

- Certifications preferred :

1. SC-200 (Microsoft Security Operations Analyst).

2. GCIH / CISSP (or equivalent).

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...