HamburgerMenu
hirist

Job Description

Role Summary : Cyber Defense / SOC Lead

Experience : 8 - 10 Years

Domain : Cyber Defense | SOC | SIEM | Threat Detection & Incident Response

Primary Technologies : Microsoft Sentinel, Microsoft Defender XDR, Defender for Endpoint, Defender for Office 365, Entra ID, Defender for Cloud Apps, Mimecast

Job Summary :

Cyber Defense professional with 8 - 10 years of experience in Security Operations, SIEM monitoring, threat detection, incident response, threat hunting and security engineering.

Responsible for operating and improving a 24x7 SOC environment, with strong hands-on experience across the Microsoft Security ecosystem, including Microsoft Sentinel, Microsoft Defender XDR, Defender for Endpoint, Defender for Office 365, Entra ID and Defender for Cloud Apps.

The role involves end-to-end investigation of security incidents, phishing and email security incidents, detection engineering, KQL-based threat hunting, SIEM content development, security monitoring, automation and continuous tuning of security controls.

Key Responsibilities :

Security Operations & Incident Response :

- Monitor and manage security incidents and alerts in Microsoft Sentinel and Microsoft Defender XDR.

- Perform end-to-end triage, investigation, containment, remediation and closure of security incidents.

- Investigate high-severity incidents involving compromised accounts, malware, ransomware, suspicious PowerShell activity, brute-force attacks, impossible travel, anomalous sign-ins and endpoint threats.

- Perform incident correlation across endpoint, identity, email, cloud and network security telemetry.

- Coordinate with IT, Infrastructure, Identity, Network, Cloud and Application teams during security incidents.

- Prepare detailed incident reports, root-cause analysis, impact assessment and remediation recommendations.

- Support 24x7 SOC operations, shift handovers, escalations and incident response processes.

Phishing & Email Security :

- Investigate phishing, malicious email, spoofing, business email compromise and credential-harvesting incidents.

- Analyze email headers, sender reputation, URLs, attachments, domains, IP addresses and other indicators of compromise.

- Perform email remediation and deletion using Mimecast / Microsoft Defender for Office 365.

- Identify malicious campaigns and hunt for similar messages across the organization.

- Coordinate with users and IT teams for compromised mailbox and credential-related incidents.

- Develop and maintain phishing investigation SOPs and response procedures.

Microsoft Sentinel / SIEM :

- Develop, maintain and fine-tune Microsoft Sentinel Analytics Rules using KQL.

- Create advanced hunting queries for suspicious authentication, endpoint, cloud and network activity.

- Perform false-positive analysis and continuously optimize detection logic.

- Develop Sentinel Workbooks and dashboards for SOC KPIs, incident trends, severity, MITRE ATT&CK techniques, MTTT and MTTR.

- Manage watchlists, threat intelligence indicators and custom detections.

- Work with multiple data sources including Entra ID, Azure Activity Logs, Defender, Mimecast, Cloud App Events, Azure services and network/security platforms.

- Troubleshoot data connector and log ingestion issues and validate data availability and quality.

Threat Hunting :

- Conduct proactive threat hunting using Microsoft Sentinel, Defender XDR and advanced KQL queries.

- Hunt for known and emerging IOCs including malicious IPs, domains, URLs, hashes and suspicious processes.

- Investigate techniques such as credential dumping, password spraying, distributed brute-force attacks, PowerShell abuse, lateral movement and ransomware activity.

- Map detections and hunting activities to the MITRE ATT&CK framework.

- Research emerging threats, malware campaigns, vulnerabilities and supply-chain attacks and translate findings into actionable detections.

Microsoft Defender / Endpoint Security :

- Monitor and investigate endpoint alerts using Microsoft Defender for Endpoint.

- Perform endpoint investigation, device isolation/containment and remediation activities.

- Analyze process trees, command lines, network connections, file activity and user behavior.

- Use Defender Live Response for advanced endpoint investigation and evidence collection.

- Investigate inactive or unhealthy Defender sensors and coordinate remediation.

- Develop endpoint-focused hunting queries and detection strategies.

Identity & Cloud Security :

- Investigate Entra ID sign-in and authentication-related incidents.

- Analyze suspicious sign-ins, failed authentication attempts, disabled-account activity, MFA-related events and anomalous user behavior.

- Investigate compromised identities and coordinate account containment and remediation.

- Monitor Azure Activity Logs, Azure resources and cloud application activity.

- Support security monitoring across Microsoft 365 and Azure environments.

Detection Engineering & Automation :

- Design and implement security detections based on threat intelligence, incident learnings and MITRE ATT&CK techniques.

- Develop Sentinel Automation Rules and Logic App playbooks for incident enrichment, notification and response.

- Automate repetitive SOC activities such as IOC enrichment, alert notifications and incident handling.

- Integrate threat intelligence sources and security platforms into the SOC ecosystem.

- Continuously improve detection coverage and reduce alert noise through tuning and automation.

SOC Process & Leadership :

- Act as a technical lead / SME for Cyber Defense and SOC operations.

- Guide junior SOC analysts during incident investigation and escalation.

- Review analyst investigations and ensure adherence to SOC processes and SLAs.

- Create and maintain SOPs, Knowledge Base articles, investigation playbooks and operational documentation.

- Conduct knowledge-transfer sessions for new technologies, threats and investigation techniques.

- Support SOC transition, onboarding and operational readiness activities.

- Track operational metrics including incident volumes, severity trends, MTTT, MTTR, SLA compliance and detection effectiveness.

Core Technical Skills :

- SIEM : Microsoft Sentinel

- EDR/XDR : Microsoft Defender for Endpoint, Microsoft Defender XDR

- Email Security : Microsoft Defender for Office 365, Mimecast

- Identity : Microsoft Entra ID / Azure AD

- Cloud Security : Microsoft Defender for Cloud Apps, Microsoft Defender for Cloud, Azure Security

- Threat Hunting : KQL, Microsoft Defender Advanced Hunting

- Automation : Sentinel Automation Rules, Logic Apps, Azure Functions

- Threat Intelligence : IOC analysis, threat feeds, IP/domain/hash reputation, MITRE ATT&CK

- Security Operations : Incident Response, Alert Triage, Threat Hunting, Detection Engineering, SOC Monitoring

- Cloud & Logging : Azure Activity Logs, Log Analytics, Azure Diagnostics, App Service Logs, Azure Front Door

- Network/Security Tools : Zscaler, Cloudflare and other security/network telemetry sources

- Endpoint Security : Microsoft Defender, McAfee Endpoint Security, Sophos

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...