Lead AI Security SOC Analyst (Microsoft 365/Azure)

KalSoft

Doha

On-site

QAR 180,000 - 300,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

KalSoft is seeking a Lead SOC Analyst to lead security monitoring, threat detection, investigation, and incident response for AI agents and agentic platforms across the Microsoft ecosystem in Doha. You will oversee AI security monitoring, incident response, compliance, and containment activities in a 24/7 SOC environment.

Requirements include a 5+ year track record in SOC/IR, hands-on MS Sentinel/Defender XDR, Purview, Entra ID, CAE, and PIM, plus strong KQL and cloud security expertise.

Qualifications

  • Bachelor's degree in a relevant discipline.
  • 5+ years in SOC/Security Operations, MSSP, or Incident Response.
  • Hands-on with Microsoft Sentinel, Defender XDR, Purview, Entra ID, CAE, and PIM.
  • Experience investigating identity-based attacks, cloud security incidents, and authorization issues.
  • Experience creating, tuning, and maintaining detection rules and workflows.
  • Experience supporting security monitoring in cloud-native and Microsoft security environments.
  • Experience in a 24/7 security operations environment.
  • Proficiency in KQL for threat hunting and investigation.
  • Understanding RBAC, PAM, least privilege, and identity governance.
  • Knowledge of AI security tech including Microsoft Copilot Studio, Microsoft 365 Agents, Azure AI Foundry.
  • Familiarity with OWASP Top 10 for LLM, MITRE ATLAS, and NIST AI RMF.

Responsibilities

  • Monitor AI agents and agentic platforms across Microsoft 365, Purview, Defender XDR, Entra ID, Sentinel, and Azure AI Foundry.
  • Detect, investigate, and respond to AI-related threats including takeover, privilege drift, prompt injection, and shadow agents.
  • Conduct security incident triage, investigation, and escalation per SOC procedures.
  • Execute containment and remediation actions such as token revocation, CA enforcement, and agent quarantine.
  • Develop, maintain, and tune detection use cases, analytics rules, and monitoring content in Sentinel and Defender XDR.
  • Manage agent risk classifications, evidence repositories, audit records, and compliance docs.
  • Perform assurance reviews, security validations, and control testing for governance compliance.
  • Track detection, response, and containment SLAs, KPIs, and KRIs.
  • Collaborate with client security, identity, governance, Microsoft support, and AI owners for threat response.
  • Support threat hunting and ongoing improvement of AI security monitoring capabilities.
  • Develop and maintain playbooks, incident response procedures, and runbooks for AI security events.
  • Participate in a 24/7 rota and on-call support for continuous security monitoring.

Skills

KQL
RBAC
PIM
Threat Hunting
Incident Response
Cloud Security
Security Monitoring
Communication

Education

Bachelor's degree in a relevant discipline

Tools

Microsoft Sentinel
Microsoft Defender XDR
Microsoft Purview
Microsoft Entra ID
Azure AI Foundry
Conditional Access (CAE)
Privileged Identity Management (PIM)

Job description

KalSoft is seeking a Lead SOC Analyst to lead security monitoring, threat detection, investigation, and incident response for AI agents and agentic platforms across the Microsoft ecosystem in Doha. You will oversee AI security monitoring, incident response, compliance, and containment activities in a 24/7 SOC environment.

Requirements include a 5+ year track record in SOC/IR, hands-on MS Sentinel/Defender XDR, Purview, Entra ID, CAE, and PIM, plus strong KQL and cloud security expertise.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead SOC Analyst
Lead SOC Analyst

KalSoft • Doha

On-site
QAR 180,000 - 300,000
AI Security Expert
AI Security Expert

Employment • Doha

On-site
QAR 279,000 - 469,000
Lead SOC Engineer: Threat Hunting & Incident Response
Lead SOC Engineer: Threat Hunting & Incident Response

Employment • Doha

On-site
QAR 250,000 - 350,000
Senior SOC Engineer
Senior SOC Engineer

Employment • Doha

On-site
QAR 250,000 - 350,000
Senior Cybersecurity Consultant
Senior Cybersecurity Consultant

Employment • Doha

On-site
QAR 437,000 - 655,000
Senior Consultant - Cybersecurity
Senior Consultant - Cybersecurity

malomatia • Doha

On-site
QAR 300,000 - 540,000
Senior Security Analyst: Threat Ops & Incident Response
Senior Security Analyst: Threat Ops & Incident Response

Mach Consultants • Qatar

On-site
QAR 250,000 - 450,000
Competitive salary
Full-time permanent role in Qatar
Cloud Security Consultant
Cloud Security Consultant

Malomatia • Doha

On-site
QAR 180,000 - 320,000
Senior Incident Lead - Microsoft Defender & SIEM
Senior Incident Lead - Microsoft Defender & SIEM

malomatia • Doha

On-site
QAR 300,000 - 540,000
L1 Cybersecurity Engineer
L1 Cybersecurity Engineer

I A M IT Technologies LLC • Doha

On-site
QAR 85,000 - 120,000