Start Date
Immediate
Expiry Date
22 Nov, 26
Salary
0.0
Posted On
24 Aug, 26
Experience
0 year(s) or above
Remote Job
Yes
Telecommute
Yes
Sponsor Visa
Yes
Skills
Industry
Information Technology & Services
Monitor security alerts and events in Microsoft Sentinel and Microsoft Defender platforms
Perform initial triage, analysis, and prioritization of alerts
Correlate events across multiple sources including endpoints, network devices, applications, servers, and cloud services
Identify false positives, escalate genuine threats, and ensure proper documentation of findings
Maintain continuous monitoring discipline across assigned shifts
Acknowledge, investigate, and respond to security incidents within defined SLAs
Follow incident response procedures, SOPs, and runbooks for handling security events
Create, update, and manage tickets in ITSM tools (e.g., ServiceNow)
Escalate incidents to SOC Lead or relevant teams based on severity and impact
Ensure timely resolution or handover of incidents across shifts
Work with Microsoft Defender suite including Defender for Endpoint, Defender for Office 365, Defender for Cloud
Investigate alerts generated from Azure Defender / Microsoft Defender tools
Support threat detection, enrichment, and basic threat hunting activities
Assist in correlating alerts between Microsoft Sentinel and Defender platforms
Follow defined SOPs, playbooks, and escalation matrices strictly
Update SOPs and runbooks based on operational learnings and new threats
Maintain accurate and complete documentation of incidents, actions taken, and outcomes
Ensure proper shift handover documentation and communication
Support implementation of automation using Microsoft Sentinel playbooks, Logic Apps, and PowerShell
Identify repetitive tasks and suggest automation opportunities
Assist in tuning detection rules and reducing false positives
Contribute to continuous improvement of SOC operations and processes
Collaborate with infrastructure, application, and security teams for incident resolution
Communicate effectively with SOC Lead and stakeholders during incidents
Publish shift-wise status reports, including incidents handled, escalations, and observations
Participate in incident reviews and knowledge-sharing sessions
Ensure adherence to SLAs, KPIs, and KRAs defined for SOC operations
Maintain quality of incident handling, documentation, and reporting
Support audit, compliance, and governance requirements
Follow organizational security policies and standards
Represents the skills you have
Find out how your skills align with this job's requirements. If anything seems off, you can easily click on the tags to select or unselect skills to reflect your actual expertise.
Hands-on experience or working knowledge of Microsoft Sentinel (SIEM)
Familiarity with Microsoft Defender / Azure Defender technologies
Basic understanding of security operations, incident response, and threat analysis
Knowledge of networking concepts (TCP/IP, DNS, VPN, firewalls)
Understanding of Windows/Linux systems and cloud environments
Strong analytical and problem-solving abilities
Good communication and reporting skills
Ability to work in a shift-based, high-pressure SOC environment
Strong attention to detail and adherence to processes
Team collaboration and willingness to learn
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field
2–5 years of experience in SOC operations, security monitoring, or incident response roles
Familiarity with KQL (Kusto Query Language) and basic scripting (PowerShell) is a plus
How To Apply:
Incase you would like to apply to this job directly from the source, please click here