jobs in Kloudynet

Kerja Sepenuh Masa, SOC Analyst Level 2 (Microsoft Security Stack) di Kloudynet Federal Territory - Maukerja

SOC Analyst Level 2 (Microsoft Security Stack)

Kloudynet

KL City, Federal Territory

Kongsi
Simpan

Lokasi Kerja

  • Jalan Sultan Mizan Zainal Abidin, Kompleks Kerajaan Kuala Lumpur Federal Territory Malaysia

Penerangan Kerja

Tanggungjawab

Role Overview:

We are looking for a SOC Analyst to join our Managed Security Operations team and work extensively with the Microsoft Security ecosystem. The analyst will be responsible for monitoring, investigating, triaging and responding to security incidents across customer environments using Microsoft Sentinel, Microsoft Defender and related security technologies.

The ideal candidate should have strong hands-on experience in SIEM monitoring, incident investigation, threat hunting, KQL and Microsoft security technologies, with the ability to distinguish genuine threats from false positives and drive incidents through to resolution.


Key Responsibilities:


L2/L3 SOC Engineer Responsibilities:

  • Monitor security alerts and incidents across Microsoft Sentinel and Microsoft Defender.
  • Perform L1/L2 security alert triage, investigation and escalation.
  • Investigate incidents using:

Microsoft Sentinel

Microsoft Defender XDR

Microsoft Defender for Endpoint (MDE)

Microsoft Defender for Office 365

Microsoft Defender for Cloud

Microsoft Entra ID

Microsoft Defender for Cloud Apps

  • Develop and use KQL queries for investigation, detection and threat hunting.
  • Analyse endpoint, identity, email, cloud, authentication and network telemetry.
  • Investigate suspicious:

Process execution

PowerShell activity

Authentication anomalies

Account compromise

Malware and ransomware

Phishing and Business Email Compromise

Impossible travel / risky sign-ins

Privilege escalation

Data exfiltration

  • Perform threat hunting across Microsoft security telemetry.
  • Analyse Indicators of Compromise (IOCs), including IP addresses, domains, URLs, hashes and suspicious accounts.
  • Correlate events across multiple data sources to reconstruct attack timelines.
  • Execute approved incident-response actions such as endpoint isolation, account containment and indicator blocking.
  • Maintain accurate incident documentation and investigation timelines.
  • Escalate complex incidents to L2/L3, Detection Engineering or Incident Response teams.
  • Tune and improve Sentinel analytics rules, queries and automation based on observed threats.
  • Support development and maintenance of Sentinel playbooks, automation rules and detection content.
  • Prepare daily, weekly and monthly SOC reports.
  • Participate in shift handovers and maintain proper SOC operational procedures.


Required Technical Skills

Microsoft Security

Strong practical knowledge of:

  • Microsoft Sentinel
  • Microsoft Defender XDR
  • Microsoft Defender for Endpoint
  • Microsoft Defender for Office 365
  • Microsoft Defender for Cloud
  • Microsoft Entra ID
  • Microsoft Defender for Cloud Apps
  • Microsoft Purview / Information Protection

SIEM & Investigation

  • Advanced KQL
  • SIEM alert investigation
  • Incident correlation
  • Threat hunting
  • MITRE ATT&CK mapping
  • IOC investigation
  • Malware analysis fundamentals
  • Windows security events
  • Authentication and identity logs
  • Network and firewall logs

Incident Response

  • Alert triage
  • Incident containment
  • Endpoint investigation
  • Phishing investigation
  • Account compromise investigation
  • Malware/ransomware investigation
  • Root-cause analysis
  • Evidence preservation
  • Incident documentation


Certifications:


Candidates should hold at least any TWO of the following certifications:

  • CompTIA Cybersecurity Analyst+ (CySA+)
  • EC-Council Certified Incident Handler (ECIH)
  • ISC2 Certified in Cybersecurity (CC)
  • ISC2 Systems Security Certified Practitioner (SSCP)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • GIAC Security Operations Certification (GSOC)
  • OffSec Defense Analyst (OSDA)
  • CREST Accredited SOC Provider
  • EC-Council SOC Analyst
  • Global ACE Certified Security Operations Centre Analyst (CSOC)
  • Cloud Security Alliance Certificate of Cloud Security Knowledge (CCSK)
  • OffSec Incident Response (OSIR)


Preferred Certification Combination


Any 2 certifications, with preference for:

CompTIA CySA+ + EC-Council Certified Incident Handler (ECIH)


This combination aligns particularly well with the role's requirements around SOC monitoring, security analysis, incident investigation and response.


Qualifications:


  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science or a related field preferred.
  • 2–5 years of experience in a SOC/MSSP environment.
  • Hands-on experience with Microsoft Sentinel and Microsoft Defender technologies.
  • Experience working in a 24×7 SOC / shift-based environment is preferred.
  • Strong understanding of the MITRE ATT&CK framework.
  • Experience with KQL-based security investigations is required.


Key Performance Expectations:


The successful candidate should be able to:


Detect → Triage → Investigate → Correlate → Contain → Escalate → Document


The role requires strong analytical thinking, attention to detail, disciplined incident handling and the ability to work effectively under time-sensitive SOC conditions.


Core Competencies:

  • Security monitoring
  • Incident response
  • Threat hunting
  • KQL
  • Microsoft Sentinel
  • Microsoft Defender
  • MITRE ATT&CK
  • Digital investigation
  • Analytical thinking
  • Clear technical communication
  • SOC process discipline
  • Shift and handover management



Peringatan Penting

Jangan pernah kongsikan maklumat bank atau kad kredit anda semasa memohon pekerjaan. Elakkan membuat sebarang pembayaran atau mengisi survey yang tidak berkaitan. Jika ada yang mencurigakan, sila laporkan iklan pekerjaan ini segera.

Lebih Lanjut