About the Role
We are looking for a proactive SOC Analyst (L1) with 3 years of experience in Security Operations to join our Managed Security Services team. The ideal candidate will be responsible for monitoring, triaging, investigating, and escalating security incidents using Microsoft Sentinel while ensuring compliance with defined SLAs and operational procedures.
This role primarily focuses on Microsoft Sentinel monitoring and incident triage, with escalation of complex incidents to the L2 Security Operations team.
Shift Details -
- Work Shift: 11:30 PM – 11:30 AM IST (Sunday to Thursday)
-
Weekends (Fridays and Saturdays) and Public Holidays will be Rotational Shift
-
Will follow 4 Days Work Week
Key Responsibilities
-
Monitor security alerts and incidents in Microsoft Sentinel.
-
Perform initial triage and validate security alerts.
-
Classify alerts based on severity and business impact.
-
Investigate suspicious activities using Sentinel logs and dashboards.
-
Follow documented SOPs, playbooks, and incident response procedures.
-
Escalate security incidents to L2 SOC analysts within defined SLAs.
-
Document investigation findings and maintain accurate incident records.
-
Perform shift handovers with detailed updates on open incidents.
-
Monitor Microsoft Sentinel health, including data ingestion and connector status.
-
Identify false positives and report recurring patterns.
-
Ensure compliance with customer SLAs and response timelines.
-
Prepare daily operational reports and shift summaries.
-
Participate in knowledge transfer sessions and continuous process improvement initiatives.
Required Skills - SIEM
-
Microsoft Sentinel (Mandatory)
-
Experience in monitoring and handling Sentinel incidents.
Microsoft Security
-
Microsoft Defender
-
Microsoft Entra ID (Azure AD)
-
Microsoft 365 Security
-
Azure Monitor
-
Log Analytics
Security Knowledge
-
Security Operations Center (SOC) processes
-
Incident Management
-
Incident Triage
-
Threat Detection
-
Basic malware analysis concepts
-
Identity and Access Management fundamentals
Tools (Good to Have)
-
Microsoft Defender XDR
-
Microsoft Defender for Endpoint
-
Microsoft Defender for Identity
-
Microsoft Defender for Office 365
-
ServiceNow
-
Jira
-
Microsoft Intune
-
Azure Portal