Location - Salem WFO
Key responsibilities
- Monitor and triage security alerts in SIEM and related tools
- Investigate phishing, malware, and account compromise incidents
- Monitor Microsoft 365 security, Exchange Online, Teams, and Compliance features
- Monitor Azure Entra ID, Conditional Access, MFA, and identity hygiene
- Operate endpoint security with Trend Micro Vision One and ManageEngine Endpoint Central
- Monitor Microsoft Intune for device compliance and configuration
- Coordinate with SOC, IT Ops, and Compliance on containment and recovery
- Maintain policies, SOPs, and incident runbooks
- Track vulnerabilities and remediation with IT teams
- Prepare weekly dashboards and RCA for major incidents
- Support audits and evidence collection
Mandatory skills
- Microsoft 365 security and compliance administration
- Exchange Online, Teams, and DLP, Anti-phishing, Safe Links, Safe Attachments
- Azure Entra ID, Conditional Access, MFA, Identity Protection
- SIEM operations and alert triage, preferably FortiSIEM
- Endpoint security operations with Trend Micro Vision One
- Device management with Intune and Endpoint Central
- Incident response, phishing investigation, email header analysis
- Log analysis, KQL or SIEM query basics, IOC enrichment
- Policy writing, SOP documentation, and audit evidence handling
- Strong stakeholder communication and transparent RCA writing
Preferred skills
- FortiGate firewall basics, policy review, and log interpretation
- EDR/XDR experience, sandboxing, and threat intelligence usage
- Knowledge of NIST CSF, ISO 27001, and CIS Controls
- Experience with vulnerability management tools and patch governance
Interested candidates can share their resumes to
[email protected]
📌 SOC Analyst - SIEM - Location Salem
🏢 Vee Healthtek
📍 Salem