Overview
Skills
Job Details
Exp: 9+
SOC Engineer Charlotte, NC (Onsite)
We are seeking a Senior Incident Response & Threat Management Lead to manage cyber incidents, threat hunting, and data protection initiatives using Microsoft security technologies. This role will lead a cybersecurity SWAT team, oversee response workflows, and ensure sensitive data is protected across hybrid environments.
Key Responsibilities:
Lead incident response using Microsoft Sentinel & Defender XDR.
Develop automated playbooks with KQL, Logic Apps, and Graph API.
Conduct threat hunting and integrate Microsoft Threat Intelligence feeds.
Manage data protection with Microsoft Purview (DLP, Insider Risk, Info Protection).
Drive SOC maturity through purple team exercises, KPIs, and detection engineering.
Mentor SOC analysts and collaborate with IT, compliance, and legal teams.
Build SOAR workflows and deploy new Microsoft security features.
Qualifications:
5+ years in cybersecurity, with 3+ in incident response, threat hunting, or data protection.
Hands-on with Microsoft Sentinel, Defender XDR, Purview, Microsoft 365 security.
Strong in KQL, Logic Apps, Graph API, MITRE ATT&CK, adversary emulation.