SOC Analyst

Remote • Posted 8 hours ago • Updated 8 hours ago
Contract W2
Contract Independent
12 Months
No Travel Required
Remote
Depends on Experience
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • SIEM
  • Security Operations
  • Microsoft Defender
  • Azure

Summary

Required Qualifications

  • SOC analyst experience, including at least 1 year in an escalation/L2 capacity...
  • Hands-on production experience with SentinelOne Singularity (Console, Deep Visibility, Storyline, RemoteOps).
  • Solid understanding of Windows/Linux/macOS internals, common attack techniques, and the MITRE ATT&CK framework.
  • Experience with case management/ticketing platforms and SIEM log review.
  • Strong written communication skills for incident documentation and playbook authoring.

Preferred Qualifications

  • SentinelOne certification(s) (e.g., SentinelOne Certified Analyst/Engineer).
  • Experience with SOAR platforms (e.g., Palo Alto XSOAR, Swimlane, Tines) for playbook automation.
  • Exposure to identity-centric investigation tools or entity/behavioral intelligence platforms.
  • Industry certifications: GCIH, GCIA, Security+, CySA+, or equivalent.
  • Prior MSSP/MDR environment experience supporting multiple client tenants.

Position Summary
Our security architecture deeply relies on Microsoft Sentinel and Microsoft Defender XDR as our cloud-native SIEM and SentinelOne as well as Microsoft Defender for Endpoint as our enterprise Endpoint Detection and Response (EDR) platform. The ideal candidate possesses a strong command of Kusto Query Language (KQL), extensive experience pivoting between endpoint forensics and cloud infrastructure logs, and a proven track record of neutralizing threats, and have deep understanding of Microsoft Azure PaaS and SaaS security technologies.

  • MUST HAVE experience here in Splunk and Splunk ES.
  • An experienced and analytical Level 2 (L2) Security Operations Center (SOC) Analyst to join customer team. In this role, act as the primary escalation point for complex security anomalies. Responsible for conducting deep-dive incident investigations, correlating cross-domain telemetry, and driving containment strategies.
  • The ideal candidate possesses a strong command of Kusto Query Language (KQL), extensive experience pivoting between endpoint forensics and cloud infrastructure logs, and a proven track record of neutralizing threats, and have deep understanding of Microsoft Azure PaaS and SaaS security technologies.
  • Advanced Incident Investigation: Analyze and validate high-priority alerts escalated by L1 analysts. Utilize Microsoft Sentinel and Defender XDR to correlate cross-platform data sources (Azure AD, Microsoft 365, network firewalls, On-prem AD, SaaS services and multi-cloud logs) to determine the true scope and impact of an incident
  • Execute containment playbooks to neutralize threats. This includes isolating compromised endpoints directly through SentinelOne  and Microsoft Defender for Endpoint, revoking compromised cloud sessions via Azure AD, and blocking malicious Indicators of Compromise (IOCs) across security perimeters.  
  • Detection Engineering & Tuning: Author, refine, and optimize Microsoft Sentinel Analytics Rules and threat hunting queries using Kusto Query Language (KQL) to minimize false positives and capture emerging threat techniques.
  • SOAR Automation: Build and modify automated response logic apps and playbooks within MS Sentinel to improve the SOC's Mean Time to Respond (MTTR Collaboration & Mentorship: Provide technical guidance, escalation support, and constructive feedback to Level 1 Analysts to uplift overall team competency.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10267472
  • Position Id: 9090814
  • Posted 8 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote

4d ago

Easy Apply

Contract

65

Remote

Today

Easy Apply

Full-time

95000 - 135000

Remote

Yesterday

Easy Apply

Contract, Third Party

Depends on Experience

Remote

Today

Easy Apply

Contract

80 - 90

Search all similar jobs