Tenarai is seeking an experienced and analytical Level 2 Security Operations Center (SOC) Analyst to join their team. In this role, you will act as the primary escalation point for complex security anomalies, conducting deep-dive incident investigations and driving containment strategies.
Key responsibilities
- Analyze and validate high-priority alerts using Microsoft Sentinel and Defender XDR to determine the scope and impact of incidents.
- Perform deep-dive investigations into malicious host behaviors using SentinelOne and Microsoft Defender for Endpoint.
- Execute containment playbooks to neutralize threats, including isolating endpoints and blocking malicious indicators.
- Author and optimize Microsoft Sentinel Analytics Rules and threat hunting queries using Kusto Query Language (KQL).
- Build and modify automated response logic apps and playbooks to improve the SOC's response time.
Requirements
- Minimum of 2-4 years of dedicated experience in an enterprise or MSSP Security Operations Center.
- Highly proficient with Microsoft Sentinel, Microsoft Defender XDR, and related log architecture.
- Advanced proficiency in KQL for data parsing, log analysis, and active threat hunting.
- Hands-on experience with SentinelOne and Defender for Endpoint.
- Practical familiarity with the MITRE ATT&CK framework and proficiency in scripting languages like PowerShell or Python.
What we offer
- Life insurance and private medical care (Platinum Package).
- Budget for professional development and access to an internal learning platform.
- Referral program with financial bonuses.
- Access to the MyBenefit platform, including sports activities.