Minimum of seven years of experience in cybersecurity, network security, security operations, incident response, or a closely related information security role.
Hands-on experience with Microsoft Sentinel, including incident management, analytics rules, workbooks, automation, data connectors, and Kusto Query Language.
Experience using SIEM for log analysis, alert investigation, dashboarding, correlation searches, and security monitoring.
Experience with NDR for network traffic analysis, packet/session investigation, threat detection, and incident support.
Experience with EDR tools, including endpoint alert triage, device investigation, advanced hunting, and response actions.
Working knowledge of network security concepts, including firewalls, IDS/IPS, proxy logs, DNS, VPN, TCP/IP, segmentation, and secure network architecture.
Ability to analyze complex security events, correlate data across multiple sources, and produce clear written documentation and recommendations.
Knowledge of security frameworks, standards, and regulatory considerations such as NIST, CIS Controls, HIPAA, and state information security requirements.
Strong communication, collaboration, problem-solving, and analytical skills.
Bachelor’s degree in cybersecurity, computer science, information systems, information technology, or a related field. Relevant experience may be considered in place of education where applicable.
Microsoft security certifications are strongly preferred, such as
Microsoft Certified: Security Operations Analyst Associate,
Microsoft Certified: Cybersecurity Architect Expert,
Microsoft Certified: Azure Security Engineer Associate, or Microsoft 365 Defender-related certifications.
Additional preferred certifications include CompTIA Security+, CySA+, GIAC security certifications, CISSP, CISM, CISA, Splunk Core Certified Power User, Splunk Enterprise Security Certified Admin, or SentinelOne product certifications.
Knowledge of SIEM, SOAR, EDR, XDR, network detection and response, log management, and threat intelligence concepts.
Skill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting.
Skill in identifying indicators of compromise, attacker tactics, suspicious network patterns, and endpoint-based threats.
Ability to prioritize alerts, document investigative steps, and escalate incidents based on severity and business impact.
Ability to work independently and collaboratively in a security operations environment with shifting priorities and time-sensitive incidents.
Ability to communicate cybersecurity risks, findings, and recommended actions to both technical and non-technical audiences.
7 Required Knowledge of SIEM, SOAR, EDR, XDR, NDR
7 Required Experience with security log collection and management
7 Required Experience with threat intelligence concepts
7 Required Skill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting
7 Required Experience in SIEM platform/architecture support
7 Required Experience in detection engineering methodology and implementation
10 Preferred Knowledge of SIEM, SOAR, EDR, XDR, NDR
10 Preferred Experience with security log collection and management
10 Preferred Experience with threat intelligence concepts
10 Preferred Skill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting
10 Preferred Experience in SIEM platform/architecture support
10 Preferred Experience in detection engineering methodology and implementation