Tech Stack
AzureCloudCyber SecurityTerraform
About the role
- Monitor, detect, analyse, and respond to security incidents as part of frontline defence
- Lead and participate in complex incident investigations, including root cause, scope, and impact analysis
- Provide guidance and mentorship to team members and resolver teams during incident response
- Coordinate containment, eradication, and recovery strategies with cross-functional teams
- Proactively threat hunt and analyse security data from logs, network traffic, and endpoints
- Develop and maintain threat profiles, TTPs, and integrate IOCs into SOC tooling
- Configure, manage, and fine-tune Microsoft Azure Sentinel including custom queries, alerts, and workbooks
- Integrate diverse data sources into Azure Sentinel for monitoring and correlation
- Identify, track, and prioritise high-risk vulnerabilities and drive remediation efforts
- Implement Azure cloud security controls (NSGs, Microsoft Defender for Cloud, Azure Policy, Azure AD) and assess compliance
- Document incident details, investigation findings, and create comprehensive incident reports and lessons learned
- Participate in continuous improvement of SOC processes and stay current with cybersecurity threats
- Communicate technical concepts to technical and non-technical stakeholders and collaborate with internal and external partners
Requirements
- Proven experience as a SOC Analyst with a strong background in cybersecurity operations, incident response, and threat detection
- In-depth understanding of security technologies including SIEM, IDS/IPS, endpoint detection and response (EDR), and network monitoring tools
- Proficiency in analysing and interpreting security logs, network traffic, and endpoint data
- Strong knowledge of cyber-attack methodologies, tactics, and techniques
- Excellent problem-solving skills and ability to work under pressure during critical incidents
- Effective written and verbal communication skills
- Flexibility to participate in an on-call rotation for after-hours support
- Ability to modify alerts within Terraform AzureRm modules
- Proficiency in KQL