Job Description

Job Description ? SOC L3 Analyst (Microsoft Sentinel SIEM)

Role Overview

We are seeking a highly skilled SOC L3 Analyst with deep expertise in Microsoft Sentinel SIEM to lead advanced security monitoring, incident response, and threat hunting activities. The role involves handling complex security incidents, developing detection use cases, and improving SOC maturity through automation and optimization.

Key Responsibilities

  • Lead end-to-end incident handling for high-severity (P1/P2) incidents using Microsoft Sentinel.
  • Perform deep-dive forensic analysis using KQL, Defender suite, and Azure AD signals.
  • Investigate advanced attack patterns such as lateral movement, privilege escalation, persistence, and data exfiltration.
  • Develop and optimize analytics rules, hunting queries, and dashboards.
  • Map detections with MITRE ATT&CK framework.
  • Optimize SIEM ingestion, connectors, and detection logic.
  • Develop automation using Logic Apps playbooks.
  • Integrate threat intelligence feeds and enable IOC correlation.
  • Act as escalation point for L1/L2 analysts and support incident RCA.
  • Prepare reports, dashboards, and ensure SLA/KPI tracking.

Required Technical Skills

  • Hands-on expertise in Microsoft Sentinel and Azure environments.
  • Strong KQL (Kusto Query Language) skills.
  • Experience with Microsoft Defender suite (MDE, MDI, MDO).
  • Knowledge of endpoint, network, and identity security.
  • Understanding of MITRE ATT&CK framework.
  • Experience with APIs, Logic Apps, and scripting (PowerShell/Python).

Preferred Skills

  • Experience with other SIEM tools like Splunk or QRadar.
  • Exposure to UEBA and XDR platforms.
  • Basic knowledge of digital forensics and malware analysis.

Certifications

  • SC-200: Security Operations Analyst
  • AZ-500: Azure Security Engineer
  • CEH, GCIH or equivalent certifications

Experience

  • 5?8 years in SOC/Cybersecurity
  • 2?3 years of hands-on Microsoft Sentinel experience

KPIs

  • Reduction in MTTD and MTTR
  • Improved detection accuracy
  • Reduced false positives
  • Enhanced automation coverage

Business Value

  • Improves threat detection in cloud-native environments
  • Reduces response time through automation
  • Enhances security visibility
  • Optimizes SIEM cost and performance

Azure Sentinel SIEM


Job Details

Role Level: Not Applicable Work Type: Full-Time
Country: India City: Bengaluru ,Karnataka
Company Website: http://www.happiestminds.com Job Function: Cybersecurity
Company Industry/
Sector:
Software Development

What We Offer


About the Company

Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.

Report

Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@talentmate.com.


Recent Jobs
View More Jobs
Talentmate Instagram Talentmate Facebook Talentmate YouTube Talentmate LinkedIn