Noida, Uttar Pradesh
Job Summary
Job Summary:
We are seeking a Level 2 Threat & Incident Response Analyst with hands-on experience in Microsoft Sentinel. The candidate will be responsible for monitoring security events, investigating incidents, and supporting response and containment activities in a SOC workplace.
Key Responsibilities
Key Responsibilities:
Monitor and investigate alerts and incidents in Microsoft Sentinel
Perform incident triage and validate alerts escalated from L1
Conduct root cause analysis (RCA) for security incidents
Analyze logs from identity, endpoint, network, and cloud environments
Correlate events across multiple sources to identify threats
Execute incident response actions such as containment and remediation
Work with threat intelligence feeds to enrich investigations
Assist in tuning analytics rules and reducing false positives
Document incidents, findings, and response activities
Support shift handovers and maintain SOC documentation
Skill Requirements
Required Skills:
Hands-on experience with Microsoft Sentinel (SIEM)
Understanding of incident response lifecycle
Knowledge of log analysis and threat detection
Familiarity with MITRE ATT&CK; framework
Knowledge of Azure security, identity (Entra ID), and endpoint security
Solid analytical and troubleshooting skills
Other Requirements
Positive to Have:
Experience in KQL query writing
Exposure to Microsoft Defender suite (MDE, MDI, MDO)
Knowledge of SOAR playbooks (Logic Apps)
Certifications (Preferred):
Microsoft SC-200
CEH / CySA+ / GCIH
Soft Skills:
Positive communication and reporting skills
Ability to work in 24x7 shift model
Team collaboration and incident handling mindset
body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-
📌 Sr Administrator Support & Operations Noida
🏢 HCLTech
📍 Noida