- Monitor and investigate cloud‑application‑related security alerts generated by Microsoft Defender for Cloud Apps (MDCA) under defined CSOC processes.
- Perform alert triage and initial investigation to determine scope, user impact, risk level, and business relevance.
- Support investigation of incidents involving risky cloud apps, OAuth abuse, data exposure, suspicious user activity, and abnormal cloud access patterns.
- Assist in containment and remediation activities in coordination with Identity, Endpoint, Email, and IT platform teams.
- Escalate complex or high‑risk cloud‑app security findings to L2/L3 specialists or Incident Managers with structured analysis and evidence.
- Analyze user behavior, activity logs, and cloud telemetry to identify anomalies and suspicious activity.
- Support policy tuning, alert refinement, and basic detection improvements to reduce false positives and improve signal quality.
- Assist with shadow IT discovery, cloud app risk assessments, and enforcement of cloud app governance policies.
- Support CSOC playbooks, runbooks, and response procedures related to cloud application security incidents.
- Participate in post‑incident reviews and RCA discussions, contributing operational findings and improvement ideas.
- Maintain accurate investigation notes, incident documentation, and response records.
- Work closely with CSOC L1/L2 analysts, Identity, Endpoint, Email Security, and IT operations teams.
- Support audit and compliance activities related to cloud application security controls when required.
Requirements
- Bachelor’s degree in computer science, Information Technology, Cybersecurity, or Engineering.
- 2 – 4 years of cybersecurity experience, with exposure to SOC operations, cloud security, or security monitoring roles.
- Hands‑on experience or operational exposure to Microsoft Defender for Cloud Apps is required.
- Experience supporting low to medium‑severity cloud or SaaS security incidents in enterprise environments is preferred.
- Certifications:
- - SC‑200: Microsoft Security Operations Analyst
Core Competencies
Demonstrates expertise in cloud application security, incident investigation, and risk assessment, with a strong focus on using Microsoft Defender for Cloud Apps. Capable of collaborating with cross-functional teams to enhance security posture and compliance.
Highest-signal resume keywords
- Microsoft Defender For Cloud Apps
- Cloud Security
- Incident Investigation
- Cybersecurity Experience
- SC-200 Certification
ATS Optimization Keywords
Hard Skills
- Alert Triage
- Risk Assessment
- Data Exposure Analysis
- User Behavior Analysis
- Cloud Telemetry Analysis
- Incident Documentation
- Policy Tuning
- Cloud App Governance
- Security Monitoring
- RCA Discussions
Soft Skills
- Collaboration
- Communication
- Analytical Thinking
- Attention To Detail
Certifications & Qualifications
- SC-200: Microsoft Security Operations Analyst
Industry Keywords
- CSOC Processes
- SaaS Security
- Shadow IT Discovery
- Cloud App Risk Assessments
- Compliance Activities