SOC Senior Analyst
Role Summary
Responsible for advanced security alert investigation, incident response, threat hunting, technical escalation, and providing guidance to SOC analysts.
Key Responsibilities
- Perform L2/L3 investigation of security alerts and incidents.
- Investigate complex and high-severity incidents across SIEM, EDR/XDR, identity, network, email, and cloud environments.
- Perform threat hunting using Indicators of Compromise (IOCs), Tactics, Techniques, and Procedures (TTPs), threat intelligence, and the MITRE ATT&CK framework.
- Analyze attack patterns, establish incident timelines, and identify root cause.
- Escalate confirmed or critical incidents within defined service-level agreements.
- Provide technical guidance and mentoring to L1/L2 analysts.
- Support detection use-case tuning and false-positive reduction.
- Perform root cause analysis and recommend corrective actions.
- Prepare incident reports and communicate findings to stakeholders.
- Participate in incident drills and tabletop exercises.
Mandatory Skills and Requirements
- 4–6+ years of SOC or cybersecurity experience.
- Hands-on experience with Microsoft Sentinel and Defender XDR/EDR, or equivalent security platforms.
- Good knowledge of Kusto Query Language (KQL) and security log analysis.
- Strong incident investigation and response skills.
- Knowledge of MITRE ATT&CK, threat intelligence, and threat hunting.
- Experience investigating malware, phishing, identity attacks, PowerShell activity, lateral movement, and data exfiltration.
- Strong analytical, communication, and escalation-management skills.
Preferred Skills
- Experience with Defender for Endpoint, Defender for Identity, Entra ID, and Microsoft Purview.
- Knowledge of Security Orchestration, Automation, and Response (SOAR), automation, and Logic Apps.
- Experience with Splunk, QRadar, ArcSight, Trellix, or Palo Alto security platforms.
- Knowledge of cloud security and User and Entity Behavior Analytics (UEBA).
Preferred Certifications
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Forensic Analyst (GCFA)
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- CompTIA Security+
- Certified Ethical Hacker (CEH)
Key Success Measures
- Accurate and timely alert investigation.
- Compliance with defined service-level agreements and effective escalation.
- Quality of incident analysis and reporting.
- Successful threat hunting and continuous detection improvement.
- Reduction in missed alerts and false positives.