Role Overview:
We are looking for a SOC Analyst to join our Managed Security Operations team and work extensively with the Microsoft Security ecosystem. The analyst will be responsible for monitoring, investigating, triaging and responding to security incidents across customer environments using Microsoft Sentinel, Microsoft Defender and related security technologies.
The ideal candidate should have strong hands-on experience in SIEM monitoring, incident investigation, threat hunting, KQL and Microsoft security technologies, with the ability to distinguish genuine threats from false positives and drive incidents through to resolution.
Key Responsibilities:
L2/L3 SOC Engineer Responsibilities:
- Monitor security alerts and incidents across Microsoft Sentinel and Microsoft Defender.
- Perform L1/L2 security alert triage, investigation and escalation.
- Investigate incidents using:
Microsoft Sentinel
Microsoft Defender XDR
Microsoft Defender for Endpoint (MDE)
Microsoft Defender for Office 365
Microsoft Defender for Cloud
Microsoft Entra ID
Microsoft Defender for Cloud Apps
- Develop and use KQL queries for investigation, detection and threat hunting.
- Analyse endpoint, identity, email, cloud, authentication and network telemetry.
- Investigate suspicious:
Process execution
PowerShell activity
Authentication anomalies
Account compromise
Malware and ransomware
Phishing and Business Email Compromise
Impossible travel / risky sign-ins
Privilege escalation
Data exfiltration
- Perform threat hunting across Microsoft security telemetry.
- Analyse Indicators of Compromise (IOCs), including IP addresses, domains, URLs, hashes and suspicious accounts.
- Correlate events across multiple data sources to reconstruct attack timelines.
- Execute approved incident-response actions such as endpoint isolation, account containment and indicator blocking.
- Maintain accurate incident documentation and investigation timelines.
- Escalate complex incidents to L2/L3, Detection Engineering or Incident Response teams.
- Tune and improve Sentinel analytics rules, queries and automation based on observed threats.
- Support development and maintenance of Sentinel playbooks, automation rules and detection content.
- Prepare daily, weekly and monthly SOC reports.
- Participate in shift handovers and maintain proper SOC operational procedures.
Required Technical Skills
Microsoft Security
Strong practical knowledge of:
- Microsoft Sentinel
- Microsoft Defender XDR
- Microsoft Defender for Endpoint
- Microsoft Defender for Office 365
- Microsoft Defender for Cloud
- Microsoft Entra ID
- Microsoft Defender for Cloud Apps
- Microsoft Purview / Information Protection
SIEM & Investigation
- Advanced KQL
- SIEM alert investigation
- Incident correlation
- Threat hunting
- MITRE ATT&CK mapping
- IOC investigation
- Malware analysis fundamentals
- Windows security events
- Authentication and identity logs
- Network and firewall logs
Incident Response
- Alert triage
- Incident containment
- Endpoint investigation
- Phishing investigation
- Account compromise investigation
- Malware/ransomware investigation
- Root-cause analysis
- Evidence preservation
- Incident documentation
Certifications:
Candidates should hold at least any TWO of the following certifications:
- CompTIA Cybersecurity Analyst+ (CySA+)
- EC-Council Certified Incident Handler (ECIH)
- ISC2 Certified in Cybersecurity (CC)
- ISC2 Systems Security Certified Practitioner (SSCP)
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- GIAC Security Operations Certification (GSOC)
- OffSec Defense Analyst (OSDA)
- CREST Accredited SOC Provider
- EC-Council SOC Analyst
- Global ACE Certified Security Operations Centre Analyst (CSOC)
- Cloud Security Alliance Certificate of Cloud Security Knowledge (CCSK)
- OffSec Incident Response (OSIR)
Preferred Certification Combination
Any 2 certifications, with preference for:
CompTIA CySA+ + EC-Council Certified Incident Handler (ECIH)
This combination aligns particularly well with the role's requirements around SOC monitoring, security analysis, incident investigation and response.
Qualifications:
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science or a related field preferred.
- 2–5 years of experience in a SOC/MSSP environment.
- Hands-on experience with Microsoft Sentinel and Microsoft Defender technologies.
- Experience working in a 24×7 SOC / shift-based environment is preferred.
- Strong understanding of the MITRE ATT&CK framework.
- Experience with KQL-based security investigations is required.
Key Performance Expectations:
The successful candidate should be able to:
Detect → Triage → Investigate → Correlate → Contain → Escalate → Document
The role requires strong analytical thinking, attention to detail, disciplined incident handling and the ability to work effectively under time-sensitive SOC conditions.
Core Competencies:
- Security monitoring
- Incident response
- Threat hunting
- KQL
- Microsoft Sentinel
- Microsoft Defender
- MITRE ATT&CK
- Digital investigation
- Analytical thinking
- Clear technical communication
- SOC process discipline
- Shift and handover management