03 Oct
|
Cloud Destinations
|
Coimbatore
03 Oct
Cloud Destinations
Coimbatore
Job Description
Lead SOC operations with a focus on Microsoft security stack, including Microsoft Sentinel, Defender suite, and email security platforms. Responsible for incident response, threat detection, and continuous improvement of monitoring capabilities.
Roles & Responsibilities
Manage end-to-end SOC operations including monitoring, triage, escalation, and closure
Lead incident response lifecycle (detection, analysis, containment, eradication, recovery)
Administer and optimize Microsoft Sentinel (analytics rules, workbooks, connectors)
Perform advanced threat hunting using Microsoft Defender (Endpoint, O365, Identity, Cloud Apps)
Investigate and respond to alerts from Defender XDR and Sentinel incidents
Manage and tune alerting to reduce false positives and improve detection accuracy
Develop, test, and maintain SIEM use cases and correlation rules
Build and maintain SOAR playbooks using Logic Apps / automation rules
Monitor and respond to email security incidents (Defender for O365)
Investigate identity-based threats and risky sign-ins in Entra ID (Azure AD)
Integrate log sources across cloud, endpoint, identity, and network platforms
Perform root cause analysis and document incident findings
Coordinate with IT, cloud, and application teams for remediation and closure
Track and report SOC metrics (MTTD, MTTR, incident trends, etc.)
Ensure compliance alignment with ISO 27001 / SOC 2 controls
Mentor SOC analysts and guide L1/L2 teams on investigations
Drive continuous improvement in detection coverage and SOC maturity
Stay updated with latest threats, vulnerabilities, and attack techniques
Requirements
Required Skills
SOC Operations & Monitoring
Microsoft Sentinel (SIEM)
Microsoft Defender Suite (Endpoint, O365, Identity)
Proofpoint / Email Security
Incident Response & Threat Hunting
Entra ID (Azure AD) Security Monitoring
📌 Soc Lead Coimbatore
🏢 Cloud Destinations
📍 Coimbatore