Job Summary
Job Summary : • Monitor, triage, investigate, and respond to security alerts using Microsoft Sentinel. • Handle escalated incidents from L1 analysts and perform detailed technical investigation. • Investigate incidents across Microsoft Defender for Endpoint, Microsoft Defender XDR, Microsoft Sentinel, Azure AD / Entra ID, email security, endpoint telemetry, and cloud logs. • Perform advanced analysis of endpoint alerts including malware execution, suspicious process activity, command-line behavior, persistence mechanisms, lateral movement, credential access, and defense evasion techniques. • Analyze Defender XDR incidents by correlating endpoint, identity, email, SaaS, and cloud signals. • Use KQL queries in Sentinel and Advanced Hunting to identify suspicious activity, validate alerts, perform threat hunting, and support incident scoping. • Determine incident severity, root cause, impacted users/devices, attack vector, timeline of events, and containment requirements. • Investigate common and advanced security incidents including phishing, malware, ransomware, credential theft, business email compromise, brute force, impossible travel, suspicious sign-ins, privilege escalation, data exfiltration, and insider threat scenarios. • Map observed attacker behavior to the MITRE ATT&CK; framework. • Conduct log analysis across endpoints, identity platforms, firewalls, proxy, DNS, VPN, servers, cloud workloads, and applications. • Perform threat hunting based on indicators of compromise, tactics, techniques, procedures, and emerging threat intelligence. • Support incident containment and remediation activities, including device isolation, account disablement, password reset, malicious email purge, IOC blocking, and endpoint remediation coordination. • Fine-tune detection rules, Sentinel analytics rules, automation rules, watchlists, and incident handling processes. • Work with SOAR playbooks and automation workflows to improve response efficiency and reduce manual effort. • Create clear and detailed incident reports covering investigation summary, technical evidence, root cause, impact, containment actions, remediation steps, and recommendations. • Mentor L2 analysts on alert triage, investigation methodology, escalation quality, and documentation standards. • Ensure adherence to SOC SLAs, escalation procedures, quality standards, and operational governance requirements. • Lead SOC governance activities including incident quality reviews, SLA tracking, escalation hygiene, operational risk identification, and continuous improvement actions. • Prepare and contribute to SOC governance reports covering ticket quality, aging incidents, breach risks, repeat alerts, false positive trends, detection gaps, and remediation status. • Act as a technical escalation point for L1 and L2 analysts and provide investigation guidance during high-severity or complex incidents.
Key Responsibilities
Job Responsibilities : • Strong hands-on experience with Microsoft Sentinel as a SIEM platform. • Strong working knowledge of Microsoft Defender for Endpoint. • Strong understanding of Microsoft Defender XDR incident correlation across endpoint, identity, email, and cloud signals. • Good experience in KQL for Sentinel investigation, log correlation, and Advanced Hunting. • Ability to investigate complex security incidents beyond basic alert review. • Strong understanding of Windows endpoint internals including processes, registry, services, scheduled tasks, PowerShell, WMI, command-line activity, persistence techniques, and malware behavior. • Good understanding of endpoint attack techniques such as credential dumping, suspicious PowerShell, encoded commands, lateral movement, privilege escalation, persistence, and defense evasion. • Ability to analyze authentication logs, risky sign-ins, MFA failures, impossible travel, conditional access events, and suspicious user activity. • Understanding of email security investigations including phishing, malicious attachments, suspicious URLs, spoofing, impersonation, and mailbox compromise. • Familiarity with Microsoft Entra ID, Azure activity logs, Microsoft 365 security logs, and cloud security signals. • Strong log analysis skills across endpoint, identity, network, firewall, proxy, DNS, VPN, and cloud sources. • Understanding of incident response lifecycle including preparation, detection, analysis, containment, eradication, recovery, and lessons learned. • Good knowledge of MITRE ATT&CK; framework and ability to map alerts and incidents to attack techniques. • Experience in detection tuning, false positive reduction, alert enrichment, and use case improvement. • Basic scripting or automation knowledge using PowerShell, Python, or Logic Apps is preferred. • Understanding of SOC operations, escalation management, severity classification, and incident documentation standards. • Strong knowledge of SOC governance practices including SLA management, ticket hygiene, escalation governance, incident quality review, operational reporting, audit support, and continuous service improvement. • Ability to review Sentinel analytics rules, incident queues, automation rules, watchlists, data connector health, log source coverage, and detection use case performance.
Skill Requirements
Skill Requirement : Investigation Skills – Mandatory The candidate must demonstrate strong investigation skills and should be able to: • Understand why an alert triggered and validate whether it is a true positive or false positive. • Build a complete incident timeline using logs from Sentinel, MDE, Defender XDR, identity, email, and network sources. • Identify initial access, execution, persistence, privilege escalation, lateral movement, command and control, and exfiltration indicators. • Analyze process trees, command-line arguments, parent-child process relationships, file hashes, network connections, login patterns, and endpoint behavior. • Correlate multiple low-level alerts into a meaningful incident narrative. • Determine the root cause, scope of compromise, impacted assets, and business risk. • Recommend containment, eradication, and remediation actions based on technical evidence. • Document findings clearly for SOC leadership, technical teams, and customer stakeholders.
Other Requirements
Other Requirement : SOC Governance Experience – Mandatory The candidate must have practical experience in SOC governance and operational oversight, including: • Reviewing SOC tickets and incidents for investigation quality, evidence completeness, severity accuracy, closure notes, and remediation tracking. • Tracking SLA performance, breach risks, escalation delays, aging incidents, repeat offenders, and operational gaps. • Driving governance calls, operational reviews, audit discussions, and service improvement actions with SOC leads, managers, and customer stakeholders. • Maintaining governance trackers, quality scorecards, incident review summaries, action item logs, and compliance evidence. • Identifying detection gaps, noisy use cases, false positive trends, automation opportunities, log source issues, and process deviations. • Supporting audit readiness by ensuring proper documentation, evidence retention, incident traceability, and adherence to agreed SOC operating procedures.