about 3 hours ago
Responsibilities
- Handle investigation and response to security incidents across various platforms.
- Act as a senior escalation point for SOC analysts during complex security events.
- Participate in on-call rotations and provide senior-level escalation support.
- Lead or contribute to post-incident reviews and track remediation actions.
- Ensure incidents are accurately documented for audit and compliance.
- Maintain and improve incident response runbooks and playbooks.
- Support incident readiness activities, including tabletop exercises.
- Develop, tune, and maintain Microsoft Sentinel analytics rules.
- Design and optimize KQL queries for investigations and threat hunting.
- Integrate and maintain log sources in Microsoft Sentinel.
- Build and maintain SOAR automation and playbooks.
- Perform proactive threat hunting to identify emerging threats.
- Monitor and improve detection coverage and security posture.
- Track and report on SOC and incident metrics.
- Partner with engineering teams for long-term remediation.
- Contribute to the continuous improvement of SOC tooling and processes.
Requirements
- Bachelor’s degree in Cyber Security, Computer Science, or related field, or equivalent experience.
- 5+ years of experience in Security Operations, Incident Response, or Detection & Response.
- Hands-on experience with Microsoft Sentinel and Microsoft Defender.
- Proficiency in KQL for investigations and detection engineering.
- Experience designing and maintaining SIEM detections and SOAR automation.
- Solid understanding of Azure cloud architecture and security controls.
- Familiarity with Azure Entra ID and identity security concepts.
- Experience handling high-severity security incidents.
- Familiarity with MITRE ATT&CK and modern attack methodologies.
- Strong communication skills for technical and non-technical audiences.
- Ability to mentor junior analysts and improve SOC processes.
- Relevant certifications such as Microsoft Security Operations Analyst Associate or similar are preferred.
Tech Stack
Azure