Senior SOC Analyst with Microsoft Security Stack, Cyber Defense Platform
- Remote.Kazakhstan
- Алмати
- Астана
- Днепър
- Ереван
- Киев
- Лвов
- Одеса
- Харков
Ако сте получили информация за тази свободна позиция от нашите рекрутери, прочетете нашата Политика за поверителност на личните данни.
Project overview
Position overview
We are looking for a Senior SOC Security Engineer with strong expertise in Microsoft security technologies and automation. You will play a key role in advancing SOC capabilities by designing automated workflows, improving detection coverage, and optimizing incident response processes using modern cloud and AI driven tools.
Responsibilities
- Manage incident detection, investigation, and response across the SOC environment
- Act as an escalation point for complex security incidents and lead end to end investigations
- Design and implement automated SOC workflows using Microsoft Copilot Studio, Azure Logic Apps, and Microsoft Sentinel
- Develop AI driven agents and SOAR playbooks to support alert triage, enrichment, and response orchestration
- Build and maintain data pipelines by onboarding, filtering, normalizing, and optimizing data within Microsoft Sentinel and Data Lake
- Create and enhance detection rules, threat hunting scenarios, and analytical models using onboarded data
- Integrate custom data sources by developing connectors and parsers to expand visibility across non standard systems
- Collaborate with teams to improve monitoring coverage and operational efficiency
- Evaluate and test new security tools and automation capabilities to continuously enhance the SOC technology stack
- Mentor team members and contribute to knowledge sharing and capability development
Requirements
- 3 to 5 years of experience in a SOC environment at L2 or Security Engineer level
- Experience acting as an escalation point for incident response and managing complex investigations end to end
- Hands on experience with malware analysis including identification of indicators of compromise and behavior analysis
- Experience with digital forensics fundamentals including evidence handling and timeline reconstruction
- Practical experience with Microsoft Sentinel including rule creation, tuning, and data onboarding
- Strong KQL skills with the ability to build and optimize analytical queries
- Experience with Microsoft Defender XDR products and advanced hunting capabilities
- Familiarity with Microsoft Azure security services including Entra ID and monitoring tools
- Experience working with AWS security services such as CloudTrail, GuardDuty, and Security Hub
- Experience with Fortinet FortiAnalyzer for log management and correlation
- Understanding of networking, operating systems, and enterprise security principles
- Experience with SOAR platforms and automation of incident response workflows
- Hands on experience with Microsoft Copilot Studio for building AI driven SOC workflows and autonomous agents
- Practical experience with Azure Logic Apps and Microsoft Sentinel playbooks for automating incident response including trigger based workflows, API integrations, and orchestration across security tools and external systems
- Experience designing and integrating Adaptive Cards within Microsoft Sentinel and Logic Apps
- Experience mentoring team members and supporting knowledge development
Nice to have
- Experience working with Microsoft Sentinel Notebooks using a Jupyter based environment for advanced investigation and data analysis
- Experience using KQL and Python to build custom analytical workflows, enrichment scenarios, and threat hunting models
Търсите сходни възможности?

