You are opening our Ukrainian language website. You can keep reading or switch to other languages.

Senior SOC Analyst with Microsoft Security Stack, Cyber Defense Platform

  • Remote.Kazakhstan
  • Алмати
  • Астана
  • Дніпро
  • Єреван
  • Київ
  • Львів
  • Одеса
  • Харків
Гаряча вакансіяСередня команда (10–20 колег)

Якщо ви отримали цю вакансію від наших рекрутерів, ознайомтеся з нашою Політикою про конфіденційність.

Project overview

This project focuses on building and enhancing a mature cyber defense capability that combines advanced incident response with security engineering and automation. The goal is to improve detection accuracy, accelerate response times, and strengthen protection across cloud and on premise systems.

Position overview

This role serves as the final escalation point for Incident Management and Incident Response within the SOC team. You will be engaged when L2 analysts encounter technically complex incidents, including malware analysis, digital forensics, high impact events, and cases with significant business or client exposure. In addition to L3 analytical responsibilities, you will contribute to engineering activities such as SIEM tuning, SOAR automation, data source onboarding, and maintaining the quality of incident tickets. You will also mentor junior analysts and support knowledge sharing across the team.

We are looking for a Senior SOC Security Engineer with strong expertise in Microsoft security technologies and automation. You will play a key role in advancing SOC capabilities by designing automated workflows, improving detection coverage, and optimizing incident response processes using modern cloud and AI driven tools.

Responsibilities

  • Manage incident detection, investigation, and response across the SOC environment
  • Act as an escalation point for complex security incidents and lead end to end investigations
  • Design and implement automated SOC workflows using Microsoft Copilot Studio, Azure Logic Apps, and Microsoft Sentinel
  • Develop AI driven agents and SOAR playbooks to support alert triage, enrichment, and response orchestration
  • Build and maintain data pipelines by onboarding, filtering, normalizing, and optimizing data within Microsoft Sentinel and Data Lake
  • Create and enhance detection rules, threat hunting scenarios, and analytical models using onboarded data
  • Integrate custom data sources by developing connectors and parsers to expand visibility across non standard systems
  • Collaborate with teams to improve monitoring coverage and operational efficiency
  • Evaluate and test new security tools and automation capabilities to continuously enhance the SOC technology stack
  • Mentor team members and contribute to knowledge sharing and capability development

Requirements

  • 3 to 5 years of experience in a SOC environment at L2 or Security Engineer level
  • Experience acting as an escalation point for incident response and managing complex investigations end to end
  • Hands on experience with malware analysis including identification of indicators of compromise and behavior analysis
  • Experience with digital forensics fundamentals including evidence handling and timeline reconstruction
  • Practical experience with Microsoft Sentinel including rule creation, tuning, and data onboarding
  • Strong KQL skills with the ability to build and optimize analytical queries
  • Experience with Microsoft Defender XDR products and advanced hunting capabilities
  • Familiarity with Microsoft Azure security services including Entra ID and monitoring tools
  • Experience working with AWS security services such as CloudTrail, GuardDuty, and Security Hub
  • Experience with Fortinet FortiAnalyzer for log management and correlation
  • Understanding of networking, operating systems, and enterprise security principles
  • Experience with SOAR platforms and automation of incident response workflows
  • Hands on experience with Microsoft Copilot Studio for building AI driven SOC workflows and autonomous agents
  • Practical experience with Azure Logic Apps and Microsoft Sentinel playbooks for automating incident response including trigger based workflows, API integrations, and orchestration across security tools and external systems
  • Experience designing and integrating Adaptive Cards within Microsoft Sentinel and Logic Apps
  • Experience mentoring team members and supporting knowledge development

Nice to have

  • Experience working with Microsoft Sentinel Notebooks using a Jupyter based environment for advanced investigation and data analysis
  • Experience using KQL and Python to build custom analytical workflows, enrichment scenarios, and threat hunting models

Шукаєте схожі можливості?

Спробуйте чат-ботів зі штучним інтелектом за допомогою нашого промпту, щоб знайти схожі вакансії, які відповідають Вашим навичкам та інтересам.
Image

We offer

Image

Відпустка

Згідно з законом вашої країни. Ми просимо обов'язково відпочити по-справжньому

Image

Страхування

Допомагаємо оформити страховку вам і вашим близьким

Image

Оплата лікарняних

10 днів без довідок від лікарів, далі — за законом вашої країни

Image

Відпочинок на свята

За офіційним календарем незалежно від клієнта

Image

Приємна обстановка

Два великі корпоративи та багато маленьких свят для колег

Image

Служба комфорту

Розв’язання технічних і побутових проблем на роботі