Posted on: 03/09/2026
Role Summary : Cyber Defense / SOC Lead
Experience : 8 - 10 Years
Domain : Cyber Defense | SOC | SIEM | Threat Detection & Incident Response
Primary Technologies : Microsoft Sentinel, Microsoft Defender XDR, Defender for Endpoint, Defender for Office 365, Entra ID, Defender for Cloud Apps, Mimecast
Job Summary :
Cyber Defense professional with 8 - 10 years of experience in Security Operations, SIEM monitoring, threat detection, incident response, threat hunting and security engineering.
Responsible for operating and improving a 24x7 SOC environment, with strong hands-on experience across the Microsoft Security ecosystem, including Microsoft Sentinel, Microsoft Defender XDR, Defender for Endpoint, Defender for Office 365, Entra ID and Defender for Cloud Apps.
The role involves end-to-end investigation of security incidents, phishing and email security incidents, detection engineering, KQL-based threat hunting, SIEM content development, security monitoring, automation and continuous tuning of security controls.
Key Responsibilities :
Security Operations & Incident Response :
- Monitor and manage security incidents and alerts in Microsoft Sentinel and Microsoft Defender XDR.
- Perform end-to-end triage, investigation, containment, remediation and closure of security incidents.
- Investigate high-severity incidents involving compromised accounts, malware, ransomware, suspicious PowerShell activity, brute-force attacks, impossible travel, anomalous sign-ins and endpoint threats.
- Perform incident correlation across endpoint, identity, email, cloud and network security telemetry.
- Coordinate with IT, Infrastructure, Identity, Network, Cloud and Application teams during security incidents.
- Prepare detailed incident reports, root-cause analysis, impact assessment and remediation recommendations.
- Support 24x7 SOC operations, shift handovers, escalations and incident response processes.
Phishing & Email Security :
- Investigate phishing, malicious email, spoofing, business email compromise and credential-harvesting incidents.
- Analyze email headers, sender reputation, URLs, attachments, domains, IP addresses and other indicators of compromise.
- Perform email remediation and deletion using Mimecast / Microsoft Defender for Office 365.
- Identify malicious campaigns and hunt for similar messages across the organization.
- Coordinate with users and IT teams for compromised mailbox and credential-related incidents.
- Develop and maintain phishing investigation SOPs and response procedures.
Microsoft Sentinel / SIEM :
- Develop, maintain and fine-tune Microsoft Sentinel Analytics Rules using KQL.
- Create advanced hunting queries for suspicious authentication, endpoint, cloud and network activity.
- Perform false-positive analysis and continuously optimize detection logic.
- Develop Sentinel Workbooks and dashboards for SOC KPIs, incident trends, severity, MITRE ATT&CK techniques, MTTT and MTTR.
- Manage watchlists, threat intelligence indicators and custom detections.
- Work with multiple data sources including Entra ID, Azure Activity Logs, Defender, Mimecast, Cloud App Events, Azure services and network/security platforms.
- Troubleshoot data connector and log ingestion issues and validate data availability and quality.
Threat Hunting :
- Conduct proactive threat hunting using Microsoft Sentinel, Defender XDR and advanced KQL queries.
- Hunt for known and emerging IOCs including malicious IPs, domains, URLs, hashes and suspicious processes.
- Investigate techniques such as credential dumping, password spraying, distributed brute-force attacks, PowerShell abuse, lateral movement and ransomware activity.
- Map detections and hunting activities to the MITRE ATT&CK framework.
- Research emerging threats, malware campaigns, vulnerabilities and supply-chain attacks and translate findings into actionable detections.
Microsoft Defender / Endpoint Security :
- Monitor and investigate endpoint alerts using Microsoft Defender for Endpoint.
- Perform endpoint investigation, device isolation/containment and remediation activities.
- Analyze process trees, command lines, network connections, file activity and user behavior.
- Use Defender Live Response for advanced endpoint investigation and evidence collection.
- Investigate inactive or unhealthy Defender sensors and coordinate remediation.
- Develop endpoint-focused hunting queries and detection strategies.
Identity & Cloud Security :
- Investigate Entra ID sign-in and authentication-related incidents.
- Analyze suspicious sign-ins, failed authentication attempts, disabled-account activity, MFA-related events and anomalous user behavior.
- Investigate compromised identities and coordinate account containment and remediation.
- Monitor Azure Activity Logs, Azure resources and cloud application activity.
- Support security monitoring across Microsoft 365 and Azure environments.
Detection Engineering & Automation :
- Design and implement security detections based on threat intelligence, incident learnings and MITRE ATT&CK techniques.
- Develop Sentinel Automation Rules and Logic App playbooks for incident enrichment, notification and response.
- Automate repetitive SOC activities such as IOC enrichment, alert notifications and incident handling.
- Integrate threat intelligence sources and security platforms into the SOC ecosystem.
- Continuously improve detection coverage and reduce alert noise through tuning and automation.
SOC Process & Leadership :
- Act as a technical lead / SME for Cyber Defense and SOC operations.
- Guide junior SOC analysts during incident investigation and escalation.
- Review analyst investigations and ensure adherence to SOC processes and SLAs.
- Create and maintain SOPs, Knowledge Base articles, investigation playbooks and operational documentation.
- Conduct knowledge-transfer sessions for new technologies, threats and investigation techniques.
- Support SOC transition, onboarding and operational readiness activities.
- Track operational metrics including incident volumes, severity trends, MTTT, MTTR, SLA compliance and detection effectiveness.
Core Technical Skills :
- SIEM : Microsoft Sentinel
- EDR/XDR : Microsoft Defender for Endpoint, Microsoft Defender XDR
- Email Security : Microsoft Defender for Office 365, Mimecast
- Identity : Microsoft Entra ID / Azure AD
- Cloud Security : Microsoft Defender for Cloud Apps, Microsoft Defender for Cloud, Azure Security
- Threat Hunting : KQL, Microsoft Defender Advanced Hunting
- Automation : Sentinel Automation Rules, Logic Apps, Azure Functions
- Threat Intelligence : IOC analysis, threat feeds, IP/domain/hash reputation, MITRE ATT&CK
- Security Operations : Incident Response, Alert Triage, Threat Hunting, Detection Engineering, SOC Monitoring
- Cloud & Logging : Azure Activity Logs, Log Analytics, Azure Diagnostics, App Service Logs, Azure Front Door
- Network/Security Tools : Zscaler, Cloudflare and other security/network telemetry sources
- Endpoint Security : Microsoft Defender, McAfee Endpoint Security, Sophos
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1668193