Key Tasks & Responsibilities:
Configure and operate Microsoft Sentinel and Microsoft Defender for continuous security monitoring and alert investigation.
Creation of Sentinel Playbooks & dashboards for platform monitoring.
Ingesting of various types of Syslog data, Network devices via Api's etc. along with proper parsing of incoming data.
Hands‑on experience working with Azure and AWS cloud environments, supporting security monitoring and investigation activities.
Develop and maintain basic to intermediate dashboards and workbooks in Sentinel using KQL, Azure Monitor Logs, and security metrics.
Perform alert tuning activities to improve detection accuracy and reduce false positives, under guidance from senior engineers.
Support documentation activities including security procedures, operational guidelines, and runbooks for SOC use.
Participate in incident investigations and provide analysis support as part of CSOC processes.
Key Skills:
Strong working knowledge of Microsoft Sentinel, Microsoft Defender, and related Microsoft security tools.
Assist with administration and operational support of Azure, AWS, and hybrid environments from a security perspective.
Good understanding of Azure architecture concepts, including compute, networking, storage, and Microsoft Entra ID.
Exposure to ingesting and parsing log sources such as Syslog, network devices, and cloud services.
Familiarity with custom connectors, scripts, or integrations for onboarding security data sources.
Understanding of SOC operations, alert lifecycle, and investigation workflows.
Experience working with SOC runbooks and operational documentation.
Basic exposure to other SIEM platforms such as Splunk, QRadar, or ArcSight is an advantage.
Good communication and collaboration skills, with the ability to work effectively with SOC teams, IT, and security stakeholders.
Bachelor’s degree in computer science, Information Technology, Cyber Security, or a related field.
Minimum of 4 to 7 years of experience in cyber security, with a focus on SIEM technologies
Certifications:
SC‑200: Microsoft Security Operations Analyst
SC‑300 / SC‑100 (foundational exposure)
CISSP / CISM (foundational knowledge or pursuing)

