SOC Microsoft Sentinel Analyst

Tata Consultancy Services

Santiago de Querétaro, Región Centro, Monterrey

Híbrido

MXN 420.000 - 640.000

Jornada completa

Hace 9 días
Generador de candidaturas

No envíes un currículum genérico: crea un currículum y una carta de presentación adaptados a este puesto concreto.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Direct contract (indeterminate time)
Legal benefits

Descripción de la vacante

Tata Consultancy Services is seeking a SOC Microsoft Sentinel Analyst to monitor, detect, investigate, and respond to cybersecurity events using Microsoft Sentinel. The candidate should be able to relocate or be located in Querétaro, CDMX, Guadalajara, or Monterrey and attend office at least 3 days per week.

The role requires strong English, 2–4 years in SOC/cybersecurity, and hands-on Sentinel experience. You will work across global teams and participate in incident response, escalation, and

Formación

  • 2–4 years of experience in SOC, SIEM, or cybersecurity operations.
  • Hands-on Microsoft Sentinel experience in an enterprise-scale monitoring environment is strongly preferred.
  • Strong investigative thinking, disciplined documentation, customer focus, ownership, and attention to detail.

Responsabilidades

  • Monitor, prioritize, and investigate alerts and incidents within Microsoft Sentinel.
  • Analyze suspicious activity across cloud, endpoint, identity, email, application, and network data sources.
  • Perform alert triage, validate the security event, determine scope and severity, and document the investigation rationale.
  • Correlate events across Microsoft Sentinel, Defender XDR, identity systems, cloud services, and integrated security tools.
  • Escalate incidents to L2/L3 or Major Incident Management according to playbooks.
  • Execute approved response actions and automated playbooks where authorized.
  • Maintain accurate incident records and handover details in ServiceNow.
  • Provide clear shift handovers and maintain follow-the-sun continuity.

Conocimientos

Advanced English communication
Microsoft Sentinel

Herramientas

Kusto Query Language
Microsoft Defender XDR
MITRE ATT&CK
NIST 800-61
Windows, AD, Entra ID

Descripción del empleo

TCS is looking for a SOC Microsoft Sentinel Analyst

(Candidate needs to be located or relocate to Querétaro, CDMX, Guadalajara or Monterrey, it will be requested to attend office at least 3 day per week)

Role Purpose

The SOC Microsoft Sentinel Analyst monitors, detects, investigates, and responds to cybersecurity events using Microsoft Sentinel and the Microsoft security ecosystem. The role supports Customer's global iSOC by delivering rapid threat detection, disciplined incident response, reliable case management, and continuous optimization of Sentinel monitoring capabilities.

Experience and Behavioral Competencies
  • Advance English communication
  • 2-4 years of experience in SOC, SIEM, or cybersecurity operations, with experience calibrated to role seniority.
  • Practical Microsoft Sentinel experience in an enterprise-scale monitoring environment is strongly preferred.
  • Strong investigative thinking, disciplined documentation, customer focus, ownership, and attention to detail.
  • Clear written and verbal communication, collaboration across global teams, and composure during high-severity incidents.
  • Ability and willingness to work within an approved 24x7 rotational shift model.
Fundamental and Required Technical Skills
  • Hands-on Microsoft Sentinel operations, alert triage, incident investigation, and case management.
  • Working proficiency in Kusto Query Language for investigation and threat hunting.
  • Understanding of Microsoft Defender XDR and its endpoint, identity, cloud, and Microsoft 365 security signals.
  • Working knowledge of MITRE ATT&CK and a structured Incident Response lifecycle; familiarity with NIST 800-61 is preferred.
  • Foundational knowledge of TCP/IP, DNS, HTTP/S, email security, firewalls, proxies, VPNs, and common network attack patterns.
  • Working knowledge of Windows, Active Directory, Microsoft Entra ID, authentication events, endpoint telemetry, and privilege-related threats.
  • Experience creating and maintaining high-quality incident records in ServiceNow or a comparable ITSM platform.
  • Security monitoring knowledge across Azure and Microsoft 365 environments.
Core Operational Responsibilities
  • Monitor, prioritize, and investigate alerts and incidents within Microsoft Sentinel.
  • Analyze suspicious activity across cloud, endpoint, identity, email, application, and network data sources.
  • Perform alert triage, validate the security event, determine scope and severity, and document the investigation rationale.
  • Correlate events across Microsoft Sentinel, Microsoft Defender XDR, identity systems, cloud services, and integrated security tools.
  • Escalate incidents to L2/L3, Major Incident Management, or other resolver groups according to playbooks and escalation matrices.
  • Execute approved response actions and automated playbooks where authorized.
  • Maintain accurate incident records, work notes, evidence, ownership, timestamps, and handover details in ServiceNow.
  • Provide clear shift handovers and maintain follow-the-sun operational continuity.
What we offer to you:
  • Direct contract (indeterminate time with initial probation period)
  • Benefits of the law and above

Tata Consultancy Services is an equal opportunity employer, our commitment to diversity & inclusion drives our efforts to provide equal opportunity to all candidates who meet our required knowledge & competency needs, irrespective of any socio-economic background, race, color, national origin, religion, sex, gender identity/expression , age, marital status, disability, sexual orientation or any others. We encourage anyone interested to build a career in TCS to participate in our recruitment & selection process.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

SOC Analyst - Microsoft Sentinel (Hybrid: 3 days in-office)
SOC Analyst - Microsoft Sentinel (Hybrid: 3 days in-office)

Tata Consultancy Services • Santiago de Querétaro, Región Centro, Monterrey

Híbrido
MXN 420.000 - 640.000
Direct contract (indeterminate time)
Legal benefits
SOC Cortex XSIAM Analyst
SOC Cortex XSIAM Analyst

Tata Consultancy Services • Jalisco

Presencial
MXN 420.000 - 660.000
Direct contract
Security Monitoring Engineer
Security Monitoring Engineer

Bosal • Santiago de Querétaro

Presencial
MXN 600.000 - 900.000
SOC Analyst L2
SOC Analyst L2

adlytics GmbH • Santiago de Querétaro

Híbrido
Horario de Oficina
Nomina 100%
Prestaciones de Ley
+2
Cortex XSIAM SOC Analyst — Threat Detection & Incident Response
Cortex XSIAM SOC Analyst — Threat Detection & Incident Response

Tata Consultancy Services • Santiago de Querétaro, Región Centro, Monterrey

Presencial
MXN 420.000 - 660.000
Direct contract
Microsoft 365 Admin Sr.
Microsoft 365 Admin Sr.

Tata Consultancy Services • Ciudad de México, Región Centro, Monterrey

Híbrido
MXN 600.000 - 900.000
Direct contract
Benefits above law
SIEM & Detection Engineer
SIEM & Detection Engineer

Bosal • Santiago de Querétaro

Presencial
MXN 859.000 - 1.204.000
SOC Analyst L2
SOC Analyst L2

Capital Empresarial Horizonte • Ciudad de México

Híbrido
Horario de oficina
Esquema 100% nómina
Prestaciones de ley
+1
SOC Analyst: Threat Detection, Incident Response & SIEM
SOC Analyst: Threat Detection, Incident Response & SIEM

Powerofconcord • Ciudad de México

Presencial
MXN 689.000 - 1.120.000
Grocery Vouchers
Internet Bonus
Medical Insurance
+3
Microsoft 365
Microsoft 365

Tata Consultancy Services • Santiago de Querétaro, Región Centro, Monterrey

Híbrido
MXN 600.000 - 1.000.000
Major Medical Insurance
Life Insurance
Grocery Vouchers
+3