Job Description
Role Purpose
The Security Operations Centre (SOC) Analyst runs the day-to-day security monitoring and alert triage function, working across the Security Information and Event Management (SIEM) platform and the wider technology stack. The role watches the environment spanning Microsoft 365, Microsoft Azure and Amazon Web Services (AWS), triaging alerts, escalating incidents and tracking endpoint and vulnerability signals.
Key Responsibilities
- Monitor the Rapid7 Security Information and Event Management (SIEM) platform and triage alerts from Microsoft Entra ID, Microsoft 365, AWS CloudTrail and AWS GuardDuty.
- Classify alert severity, run the incident workflow and elevate confirmed incidents through the escalation matrix.
- Triage Endpoint Detection and Response (EDR) alerts and track endpoint coverage gaps for follow‑up.
- Track vulnerability and patch signals from scanning across Azure and AWS, and follow items through to remediation.
- Maintain accurate triage notes, incident records and shift handover documentation, and take part in tabletop and incident response simulation exercises.
Parallel and Cross-Functional Responsibilities
- Support the Security Operations Engineer on SIEM alert tuning and refining detection metrics.
- Feed EDR and endpoint health findings to the M365 Engineer for hardening and coverage fixes.
- Provide monitoring input to the vCISO for the monthly cybersecurity reporting and dashboard.
Technical Environment
- Rapid7 as the primary Security Information and Event Management (SIEM) and vulnerability tracking platform across the environment.
- Microsoft 365 E3 with Microsoft Defender, Microsoft Intune and Microsoft Entra ID as native telemetry sources.
- CrowdStrike or Microsoft Defender for Endpoint Detection and Response (EDR), the Netskope suite for secure web gateway and Data Loss Prevention (DLP), Cloudflare for Web Application Firewall (WAF) protection and LastPass for password management.
- Amazon Web Services (AWS) and Microsoft Azure
Qualifications and Requirements
Required Skills and Experience
- Demonstrated experience monitoring and triaging alerts in a Security Information and Event Management (SIEM) platform.
- Sound understanding of alert severity classification, incident workflow and escalation practice.
- Practical monitoring experience across Amazon Web Services (AWS) and Microsoft Azure cloud environments.
- Confident working with Microsoft 365 E3 and Microsoft Entra ID sign-in and audit signals, plus knowledge of Endpoint Detection and Response (EDR) and vulnerability management concepts.
- Strong written English and clear communication for incident notes, handovers and cross-team collaboration.
Highly Desirable
- Hands‑on experience with Rapid7 or Microsoft Sentinel and the wider security tooling stack for monitoring and triage.
- Familiarity with Rapid7 or Microsoft Sentinel and Microsoft Defender or CrowdStrike detection and hunting workflows.
- Exposure to the Netskope suite and Cloudflare protection services, and understanding of the Essential Eight and Centre for Internet Security (CIS) benchmarks.
- A security certification such as Microsoft Certified: Security Operations Analyst Associate or CompTIA Security+.
Perks and Benefits
- Comprehensive health and life insurance on your 16th day of employment, covering 1 free dependent on the 16th day of employment
- Up to 24 leave credits per year
- Flexible leave credits which may be used for vacation, emergency and sick leaves
- Superb and exciting Mid-Year Parties – with items to give away and cash prizes!
- Endless opportunities for career advancement
- Exclusive ATM inside the office for employee's convenience
- Annual Performance Review with Salary Increase
- We set you up for success with a company-provided PC/Laptop and fiber internet connection
- Look forward to weekly office perks for work from office staff – Free Coffee, Meals and Beer Fridays!
- Top notch workplace with first class VIP lounge and game rooms
- Child friendly spaces to cater to the needs of employees with children, enhancing work-life balance
- Participate and join our CS Social Clubs and Special Interest Groups to connect with colleagues
- International career growth and connections
- Unlimited cash incentives for hired referrals
- Mental Wellness Employee Assistance program through Lifeworks
- In-house psychiatrist available to support employees' well-being
- Become part of the Employee Share Units program
- Cloudstaff Dream Points - To be used for bidding useful items like appliances, kitchenettes etc.