Role Overview
The SOC Specialist is a technical security resource responsible for advanced monitoring, complex incident investigation, threat detection, threat hunting, detection-engineering support, and technical escalation. The role provides specialist-level expertise to SOC analysts and supports the continuous improvement of SOC detection and response capabilities.
Key Responsibilities
- Perform advanced investigations of complex, high-risk, and escalated security incidents.
- Analyze events across SIEM, EDR/XDR, identity, network, email, cloud, firewall, proxy, application, and related security logs.
- Correlate multiple data sources to establish the attack timeline, entry point, affected assets, user impact, and overall scope.
- Investigate suspicious processes, PowerShell activity, scripts, persistence, credential abuse, lateral movement, privilege escalation, and data exfiltration.
- Conduct proactive threat hunting using indicators of compromise, tactics, techniques and procedures, behavioral indicators, hypotheses, and threat intelligence.
- Map observed activities to MITRE ATT&CK techniques and identify attack progression.
- Validate threat-intelligence indicators and assess their relevance to the environment.
- Review and tune SIEM analytics, detection logic, correlation rules, and alert thresholds.
- Identify detection gaps, recommend new security use cases, and reduce recurring alerts and false positives.
- Support major incident response, containment, eradication, recovery, and root-cause analysis activities.
- Provide technical guidance and mentoring to L1 and L2 SOC analysts.
- Support alert drills, tabletop exercises, threat simulations, and incident-response testing.
- Coordinate remediation with infrastructure, endpoint, network, identity, cloud, application, and security teams.
- Prepare detailed technical investigation reports and present findings to SOC management and customers.
- Maintain investigation procedures, playbooks, hunting documentation, and technical knowledge articles.
Required Experience and Qualifications
- 5–7+ years of hands-on SOC or cybersecurity experience.
- Proven experience in L2/L3 security monitoring, incident investigation, and technical escalation.
- Experience handling critical and high-severity incidents in an enterprise SOC, MDR, or MSSP environment.
- Strong hands-on experience with Microsoft Sentinel or an equivalent enterprise SIEM.
- Strong hands-on experience with Microsoft Defender XDR, Defender for Endpoint, or an equivalent EDR/XDR platform.
- Strong KQL knowledge, with the ability to independently query and correlate security data.
- Strong knowledge of incident response, threat hunting, threat intelligence, MITRE ATT&CK, IOC/TTP analysis, endpoint investigation, identity and authentication attacks, network security analysis, email and phishing investigation, malware and ransomware investigation, PowerShell and command-line analysis, lateral movement, privilege escalation, persistence mechanisms, and data exfiltration.
- Strong technical documentation and report-writing skills.
- Ability to communicate complex security findings to technical and non-technical stakeholders.
- Ability to challenge investigation findings, provide technical recommendations, mentor junior analysts, and improve investigation quality.
Independent Investigation Capabilities
- Build an end-to-end attack timeline.
- Identify the initial access vector and affected entities.
- Determine whether an alert is a true positive or false positive.
- Identify related users, devices, IP addresses, domains, hashes, processes, and accounts.
- Determine the incident scope and potential business impact.
- Recommend containment and remediation actions.
- Identify detection gaps following an incident.
Preferred Experience and Knowledge
- Experience with Defender for Identity, Defender for Cloud, Microsoft Entra ID, Microsoft Purview, and Intune.
- Experience with SOAR, Logic Apps, playbooks, and security automation.
- Experience with Trellix, Palo Alto, Splunk, QRadar, or ArcSight.
- Knowledge of UEBA and behavioral analytics.
- Experience with Google Threat Intelligence or other threat-intelligence platforms.
- Knowledge of malware analysis and digital forensics.
- Experience developing Microsoft Sentinel analytics rules and advanced hunting queries.
- Knowledge of Azure, AWS, or Google Cloud security.
- Experience in SIEM/EDR migration or SOC transformation projects.
Preferred Certifications
- GCIH – GIAC Certified Incident Handler
- GCFA or GCIA
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- CISSP
- CompTIA Security+ or CEH
Key Performance Indicators
- Accurate and timely resolution of complex security incidents.
- Quality of advanced investigations and incident documentation.
- Effective threat hunting and identification of previously unknown threats.
- Reduction in missed detections and false positives.
- Improvement in detection and use-case coverage.
- Timely technical escalation and remediation.
- Quality of root-cause analyses and corrective-action recommendations.
- Effective technical mentoring of SOC analysts.