Hi,
we are hiring for
Description:
Job Title: SOC Sentinel Analyst L3
Role Overview
The SOC Sentinel Analyst L3 is a senior-level security operations role responsible for advanced threat detection, incident response, and SIEM engineering using Microsoft Sentinel. This role involves handling complex security incidents, developing detection use cases, fine-tuning SIEM rules, and driving continuous improvement in SOC capabilities.
Key Responsibilities
- Lead investigation and response for complex and high-severity security incidents escalated from L1 and L2 teams.
- Design, develop, and optimize detection use cases in Microsoft Sentinel based on TTPs, threat intelligence, and emerging attack patterns.
- Create and maintain analytics rules, KQL queries, playbooks, and automation workflows to enhance detection and response capabilities.
- Continuously tune and enhance SIEM alerts to reduce false positives and improve detection accuracy.
- Integrate threat intelligence feeds and map detections to MITRE ATT&CK framework.
- Lead root cause analysis (RCA) and post-incident reviews to identify gaps and recommend improvements.
- Mentor and guide L1/L2 analysts, improving investigation quality and SOC maturity.
- Collaborate with stakeholders across security, IT, and engineering teams to strengthen security posture.
- Ensure compliance with SOC processes, SOPs, and security frameworks.
Required Skills & Qualifications
- Strong hands-on experience with Microsoft Sentinel (SIEM)
- Expertise in KQL (Kusto Query Language) for detection engineering and threat hunting
- Deep understanding of cybersecurity concepts, attack vectors, and incident response lifecycle
- Knowledge of MITRE ATT&CK framework, TTPs, and threat intelligence integration
- Experience with log sources such as Azure AD, Defender suite, Firewalls, EDR, and Cloud platforms
- Proficiency in automation tools (Logic Apps / SOAR)
- Strong analytical, problem-solving, and decision-making skills
- Excellent communication and stakeholder management abilities
Preferred Qualifications
- Certifications such as:
- Microsoft SC-200 (Security Operations Analyst)
- CEH / CISSP / GCIA / GCIH
- Experience with cloud security (Azure/AWS)
- Scripting knowledge (PowerShell, Python)
Education Qualification
- Degree in Computer Science, Information Technology, Information Services, or similar
Experience
- 68+ years of experience in SOC / Cyber Security operations
- Minimum 2-3 years working specifically with SIEM engineering and Microsoft Sentinel
Key Competencies
- Leadership and mentoring capability
- Strong ownership and accountability
- Proactive threat hunting mindset
- Continuous improvement and innovation focus
- Ability to work under pressure and manage critical incidents