About the Role:
We are seeking a highly skilled Senior SOC Analyst to join our cybersecurity team and support 24/7 security operations in partnership with an MDR provider. This role focuses on hands-on threat monitoring, incident response, and detection engineering across a modern Microsoft security ecosystem.
You will play a critical role in identifying, analyzing, and responding to cyber threats, while continuously improving detection capabilities and reducing response times.
Key Responsibilities:
- Monitor, triage, and investigate security alerts across Microsoft Sentinel and Defender XDR environments
- Perform incident response activities including containment, eradication, and recovery
- Collaborate with MDR provider (e.g., Expel) for alert escalation, validation, and resolution
- Analyze alerts from Microsoft Defender (Endpoint, Identity, Cloud Apps, Office 365)
- Investigate and respond to alerts from Zscaler (ZIA/ZPA) and Proofpoint email security
- Develop and tune KQL queries, analytics rules, and detection logic in Microsoft Sentinel
- Execute and improve SOAR playbooks and automation workflows
- Perform root cause analysis and post-incident reviews
- Reduce false positives and improve signal-to-noise ratio across tools
- Leverage frameworks such as MITRE ATT&CK for threat analysis and mapping
- Contribute to the development and maintenance of incident response playbooks and runbooks
- Track and support improvement of key SOC metrics such as MTTD, MTTR, and alert quality
- Produce detailed incident reports and communicate findings to stakeholders
- Stay updated on emerging threats, vulnerabilities, and attack techniques
Required Skills & Experience:
7–10 years of experience in Security Operations / SOC / Incident Response
Strong hands-on experience with:
- Microsoft Sentinel (SIEM)
- Microsoft Defender XDR
Proficiency in KQL (Kusto Query Language) for detection and investigation
Experience working with an MDR provider (preferred but not mandatory
Knowledge of Zscaler (ZIA/ZPA) Proofpoint email security
Strong understanding of
- Incident response lifecycle
- Threat detection & analysis
- Log analysis and correlation
Familiarity with MITRE ATT&CK framework
Experience with SOAR and automation workflows
Strong analytical and problem-solving skills
Certifications preferred
- SC-200 (Microsoft Security Operations Analy
- GCIH / CISSP (or equivalent)