You are opening our English language website. You can keep reading or switch to other languages.

Senior SOC Analyst with Microsoft Security Stack, Cyber Defense Platform

  • Almaty
  • Astana
  • Dnipro
  • Kharkiv
  • Kyiv
  • Lviv
  • Odesa
  • Remote.Kazakhstan
  • Yerevan
Hot vacancyMedium team (10-20 people)

If you received this vacancy from our recruiters — read our Privacy Notice.

Project overview

This project focuses on building and enhancing a mature cyber defense capability that combines advanced incident response with security engineering and automation. The goal is to improve detection accuracy, accelerate response times, and strengthen protection across cloud and on premise systems.

Position overview

This role serves as the final escalation point for Incident Management and Incident Response within the SOC team. You will be engaged when L2 analysts encounter technically complex incidents, including malware analysis, digital forensics, high impact events, and cases with significant business or client exposure. In addition to L3 analytical responsibilities, you will contribute to engineering activities such as SIEM tuning, SOAR automation, data source onboarding, and maintaining the quality of incident tickets. You will also mentor junior analysts and support knowledge sharing across the team.

We are looking for a Senior SOC Security Engineer with strong expertise in Microsoft security technologies and automation. You will play a key role in advancing SOC capabilities by designing automated workflows, improving detection coverage, and optimizing incident response processes using modern cloud and AI driven tools.

Responsibilities

  • Manage incident detection, investigation, and response across the SOC environment
  • Act as an escalation point for complex security incidents and lead end to end investigations
  • Design and implement automated SOC workflows using Microsoft Copilot Studio, Azure Logic Apps, and Microsoft Sentinel
  • Develop AI driven agents and SOAR playbooks to support alert triage, enrichment, and response orchestration
  • Build and maintain data pipelines by onboarding, filtering, normalizing, and optimizing data within Microsoft Sentinel and Data Lake
  • Create and enhance detection rules, threat hunting scenarios, and analytical models using onboarded data
  • Integrate custom data sources by developing connectors and parsers to expand visibility across non standard systems
  • Collaborate with teams to improve monitoring coverage and operational efficiency
  • Evaluate and test new security tools and automation capabilities to continuously enhance the SOC technology stack
  • Mentor team members and contribute to knowledge sharing and capability development

Requirements

  • 3 to 5 years of experience in a SOC environment at L2 or Security Engineer level
  • Experience acting as an escalation point for incident response and managing complex investigations end to end
  • Hands on experience with malware analysis including identification of indicators of compromise and behavior analysis
  • Experience with digital forensics fundamentals including evidence handling and timeline reconstruction
  • Practical experience with Microsoft Sentinel including rule creation, tuning, and data onboarding
  • Strong KQL skills with the ability to build and optimize analytical queries
  • Experience with Microsoft Defender XDR products and advanced hunting capabilities
  • Familiarity with Microsoft Azure security services including Entra ID and monitoring tools
  • Experience working with AWS security services such as CloudTrail, GuardDuty, and Security Hub
  • Experience with Fortinet FortiAnalyzer for log management and correlation
  • Understanding of networking, operating systems, and enterprise security principles
  • Experience with SOAR platforms and automation of incident response workflows
  • Hands on experience with Microsoft Copilot Studio for building AI driven SOC workflows and autonomous agents
  • Practical experience with Azure Logic Apps and Microsoft Sentinel playbooks for automating incident response including trigger based workflows, API integrations, and orchestration across security tools and external systems
  • Experience designing and integrating Adaptive Cards within Microsoft Sentinel and Logic Apps
  • Experience mentoring team members and supporting knowledge development

Nice to have

  • Experience working with Microsoft Sentinel Notebooks using a Jupyter based environment for advanced investigation and data analysis
  • Experience using KQL and Python to build custom analytical workflows, enrichment scenarios, and threat hunting models

Looking for Similar Opportunities?

Try AI chatbots with our ready-made prompt to discover similar roles that match your skills and interests.
Image

We offer

Image

Vacation

As per the laws of your country. We do ask you to take a proper rest

Image

Health insurance

We help you to take out an insurance policy for you and your loved ones

Image

Sick pay

10 days without a doctor's note, afterwards - as per the laws of your country

Image

Time off for state holidays

According to the official calendar, regardless of the client’s schedule

Image

Pleasant environment

Two large corporate parties and many small get-togethers for colleagues

Image

Comfort service

Solving technical and everyday problems at work

The benefits package may vary depending on the region and the type of contract

FAQ for Candidates

Work on global projects, grow your career in a supportive, flexible, and innovative tech environment. We help cover the cost of IT certifications and provide access to top-tier courses and learning platforms. View current openings and take the next step with us.

DataArt is a global software engineering company that helps businesses build powerful data, analytics, and AI solutions. We work with clients across a range of industries — including Finance, Healthcare & Life Sciences, Consumer Goods & Retail, Travel, Media & Entertainment, Mobility, and Manufacturing.

Learn more about what we do here.

DataArt supports flexible work formats to help you find the balance that works best for you. You can choose to work from the office, go hybrid, or stay fully remote—each option comes with equal opportunities for growth. We’ll help set you up with secure access and the equipment you need. With 46 remote and onsite official locations, you can join us from almost anywhere in the world.

Learn more about how we work here.

At DataArt, we put people first—fostering a culture built on trust, flexibility, and professional growth. We believe in open communication, mutual respect, and the freedom to choose how and where you work. Diversity, equity, and inclusion are core to our values, and we actively support a workplace where everyone can thrive. From mental health support to global sustainability efforts, we aim to create a healthy, empowering environment for all.

Read more about our culture and values.

There's no one-size-fits-all career path at DataArt—your growth is yours to shape. Whether you want to deepen your technical skills, move into management or sales, or even switch professions entirely, you'll have the support to do it. With exam fees fully covered, you can also earn professional certifications, like AWS, Azure, or Google Cloud. With tools like the Professional Development Map, the Talent Lab, and access to expert mentoring, we help you build your desired career.

Learn how we support both newcomers starting their careers and experienced professionals looking to grow further.

DataArt offers competitive compensation along with a range of thoughtful benefits that support your well-being, growth, and daily comfort. You’ll get flexible vacation and sick leave, mental health programs, and access to a corporate laptop or BYOD option. We also offer bonuses for referrals, parental leave, and smooth exit and return-to-work options.

Read more about how things work at DataArt.

At DataArt, we focus on creating an environment where people want to stay and grow. With 95% of employees recommending us to a friend on Glassdoor and a 100% CEO approval rating, we’re proud of the trust we’ve built. From mentoring programs and professional development services to support and conflict resolution programs, we invest in our colleagues' growth and wellbeing—because when people feel valued, they stick around.

Learn more about our company >here.

Our interview process is designed to be thorough, transparent, and supportive. It starts with a CV review, followed by an HR interview to discuss your background and goals. You'll then go through communication and technical assessments, where we evaluate your English skills and knowledge of relevant technologies. If all goes well, you’ll meet someone from the project team to learn more about the work, and we’ll guide you every step of the way—including helping you prep for any client interviews.

Read more and get tips for each stage here.

DataArt looks for candidates with strong technical skills, analytical thinking, and a commitment to continuous learning. We value experience in relevant technologies and industries, adaptability, and excellent communication skills. If you’re a junior or just starting out, don’t worry—our mentorship programs and training will support your growth from day one. The most important thing is your willingness to learn and develop professionally in our collaborative, people-first environment.

Read more about development in DataArt.

At DataArt, continuous learning is part of our culture. You’ll have access to expert mentors, leadership guidance, and thousands of courses from top platforms like Udemy and LinkedIn Learning. You can shape your own path—whether it’s growing within your role or switching to a new one.

Explore how we support your growth.