Note : We need someone with one year Practical experience in Sentinel tool.Freshers do not apply
Role overview
The analyst will be at the front line of the Security Operations Center, monitoring, investigating, and escalating security events which are generated in Microsoft Sentinel and other Microsoft Defender products. Identify false positives, threats, raise alerts, document your findings, and hand over enriched incidents to L2/L3 teams and response teams.
Responsibilities
- Realtime monitoring of alerts and incidents in Microsoft Sentinel.
- Draft and refine Kusto Query Language (KQL) queries to identify threats, reduce noise and help with investigation
- Verify file hash / IP reputation and user context based on asset criticality using internal and external threat intel sources
- Escalate to L2 or Incident Response teams as per escalation matrix or defined playbooks
- Create and maintain transparent alert tickets
- Participate in daily shift handoffs, clearly communicating status and pending actions.
- Follow documented playbooks
- Recommend tuning adjustments to improve detection capability
- Contribute to continuous improvement by sharing lessons learned.
Technical Skills
- Network basics: TCP/UDP ports, HTTP/S, DNS, VPN etc.
- Windows & Linux log fundamentals: familiarity with common Event IDs, syslog severities, authentication and process events
- Experience with Microsoft Sentinel SIEM with activities such as portal navigation, incident queue handling, rule management
- Ability to understand, write and modify existing queries for log search and alert tuning
- Understanding of Azure AD & Microsoft 365 sign in logs, Conditional Access, Defender alerts etc.
- Knowledge of MITRE ATT&CK; mapping for understanding alerts
- Experience using Virus Total, MS Threat Intelligence, WHOIS etc. for quick investigation
- Ticketing and disciplined issue tracking
Required Soft Skills
- An analytical mindset to be able to understand and document alerts
- Have an eye for detai