16 Aug
|
Important Group
|
India
16 Aug
Important Group
India
Job Description
Lead SOC operations with a focus on Microsoft security stack, including Microsoft Sentinel, Defender suite, and email security platforms. Responsible for incident response, threat detection, and continuous improvement of monitoring capabilities.
Roles & Responsibilities
- Manage end-to-end SOC operations including monitoring, triage, escalation, and closure
- Lead incident response lifecycle (detection, analysis, containment, eradication, recovery)
- Administer and optimize Microsoft Sentinel (analytics rules, workbooks, connectors)
- Perform advanced threat hunting using Microsoft Defender (Endpoint, O365, Identity, Cloud Apps)
- Investigate and respond to alerts from Defender XDR and Sentinel incidents
- Manage and tune alerting to reduce false positives and improve detection accuracy
- Develop, test, and maintain SIEM use cases and correlation rules
- Build and maintain SOAR playbooks using Logic Apps / automation rules
- Monitor and respond to email security incidents (Defender for O365)
- Investigate identity-based threats and risky sign-ins in Entra ID (Azure AD)
- Integrate log sources across cloud, endpoint, identity, and network platforms
- Perform root cause analysis and document incident findings
- Coordinate with IT, cloud, and application teams for remediation and closure
- Track and report SOC metrics (MTTD, MTTR, incident trends, etc.)
- Ensure compliance alignment with ISO 27001 / SOC 2 controls
- Mentor SOC analysts and guide L1/L2 teams on investigations
- Drive continuous improvement in detection coverage and SOC maturity
- Stay updated with latest threats, vulnerabilities, and attack techniques
Requirements
Required Skills
SOC Operations & Monitoring
Microsoft Sentinel (SIEM)
Microsoft Defender Suite (Endpoint, O365, Identity)
Proofpoint / Email Security
Incident Response & Threat Hunting
Entra ID (Azure AD) Security Monitoring
📌 SOC Lead (India)
🏢 Important Group
📍 India