Overview
In this role, you will be a key member of a 24×7 SOC, detecting and responding to threats across diverse environments. You’ll triage events using SIEM, EDR, network monitoring, and threat intel, delivering actionable risk assessments to clients. You’ll contribute to projects that enhance detection and response capabilities, including threat hunting and malware analysis. You work in a high-trust, collaborative team, shaping cutting-edge security services and close engagement with customers.
Responsibilities
- Operate as part of the 24×7 SOC Monitor Team delivering proactive defensive monitoring for clients
- Generate detailed incident reports with recommendations, mitigations, and remediations
- Respond to alerts and customer requests within agreed SLAs
- Stay abreast of defensive monitoring technologies and threat trends
- Maintain understanding of current threats and cybercrime developments
- Produce high-quality management and operational reports within SLAs
- Tune and improve alerts, playbooks, and automation
- Maintain regular written and verbal communication with customers, suppliers, and internal teams
Key requirements
- Experience with Microsoft Sentinel and Microsoft Defender (Defender for Endpoint, Identity, Cloud Apps) in deployment, configuration, and day-to-day management
- Knowledge of SIEM and EDR/ EPP tech, with focus on using Microsoft tools for threat detection, investigation, and response
- Ability to operate in a complex enterprise security environment and enhance visibility and incident response with Microsoft tools
- Experience conducting security investigations using large datasets and knowledge of Kusto Query Language (KQL) to develop custom Sentinel queries
- Solid understanding of Windows and Linux, networking, and integration of third-party security tools with the Microsoft ecosystem
- Experience analyzing security data in Sentinel and Defender portals to identify patterns and provide actionable recommendations
- Understanding of attack vectors, MITRE ATT&CK, and adversary behaviors; ability to distinguish normal vs. abnormal activity
- Excellent communication skills for customer-facing roles and conveying technical findings to diverse stakeholders using dashboards and reporting tools
- Excellent communication
- Customer-facing collaboration
- Attention to detail
- Microsoft Sentinel
- Defender (Endpoint, Identity, Cloud Apps)
- SIEM/EDR technologies
…
