Security Operations Center Analyst

Insight GlobalUnited States
Full TimeOn-siteMidLimited info disclosed
32 views0 applications

Description

Job Title: SOC Lead Incident Responder - Tier 1 Location: REMOTE; ET Hours (8am-5pm M-F) Duration: 6 Month Contract-to-Hire Opportunity Salary : $70k-90k+/year Role Summary The SOC Lead Incident Responder (Tier 1) serves as the primary point of contact for security alerts and is responsible for triaging, investigating, and leading the response to cybersecurity incidents as part of the SOC team. This is a hands-on technical role focused on rapid detection and containment using the organization's Microsoft security stack. While not a people-management position, the responder takes the lead on coordinating incident response activities and guiding fellow analysts through the response process. Key Responsibilities Monitor, triage, and investigate security alerts and events in Microsoft Sentinel (Azure SIEM). Lead the response to active security incidents, coordinating containment, eradication, and recovery steps with the SOC team. Perform endpoint investigation and containment actions using Microsoft Defender (EDR), including isolating devices and analyzing threat artifacts. Investigate identity-related threats and suspicious sign-in activity through Microsoft Entra ID (sign-in logs, conditional access, risky users/sign-ins). Document incidents thoroughly, maintaining accurate records, timelines, and handoff notes. Escalate complex or high-severity incidents to higher tiers as appropriate, with clear context and analysis. Contribute to tuning detection rules and reducing false positives within Sentinel. Follow established incident response playbooks and help keep them current. Required Skills & Experience Hands-on experience with Microsoft Sentinel (Azure SIEM): alert triage, investigation, and basic KQL queries. Proficiency with Microsoft Defender (EDR): endpoint investigation, alert analysis, and containment actions. Working knowledge of Microsoft Entra ID: identity protection, sign-in log analysis, and conditional access concepts. Solid understanding of incident response fundamentals (detection, triage, containment, eradication, recovery, lessons learned). Familiarity with common attack techniques and frameworks (e.g., MITRE ATT&CK). Strong analytical, communication, and documentation skills. Ability to remain calm and lead under pressure during active incidents. Preferred Qualifications Relevant certifications such as SC-200, AZ-500, CompTIA Security+, or equivalent. Prior experience in a SOC or incident response environment.