Senior SOC Analyst (Microsoft Azure Sentinel)

Posted 2 Days Ago
Be an Early Applicant
Hiring Remotely in Sofia, Sofia-grad, BGR
Remote or Hybrid
Senior level
eCommerce • Software
The Role
Lead advanced alert investigations, coordinate incident response and containment, integrate threat intelligence, tune SIEM/EDR detections, maintain SOPs and runbooks, document incidents, and support audits and 24/7 SOC operations with Microsoft Sentinel and Defender.
Summary Generated by Built In

About us:

AIOPSGROUP, a valantic company, is a multidisciplinary digital competency center that builds extensive e-commerce expertise and a track record of successfully delivered projects. We provide specialized services at the intersection of e-commerce, data, and technology. Our portfolio includes Consulting, Customer Acquisition & Retention, Commerce Implementation, CX Monitoring, and 24/7 Support Services. We are committed to helping global enterprise clients achieve sustainable digital growth, while maintaining strong client relationships and delivering meaningful results.

valantic is a leading provider of digital transformation services and one of the most dynamic companies in the fields of digital solutions, consulting, and software. The company is trusted by numerous major brands and internationally recognized organizations. With its unique structure of divisions, competence centers, and expert teams, valantic offers solutions tailored precisely to the digitalization needs of modern businesses—from strategy to implementation.


What Are You Going to Do?

We are looking for a Staff Security Operations Analyst to join our Security team. In this role, you will be responsible for managing internal Corporate Security posture, monitoring security anomalies, building additional detections and visibility mechanisms, and ensuring the overall security of our internal systems. You will work closely with various teams to support audits, optimize visibility, and handle security incidents as they arise.

Please note that this role may require on-call shifts.


Main Responsibilities:

  • Advanced Alert Investigation: Act as the primary escalation point for Tier 1 analysts, performing deeper correlation and behavioral analysis on complex, multi-stage security events. 
  • Incident Response & Containment: Coordinate and execute tactical containment actions (e.g., host isolation, credential revocation, network blocks) during active, confirmed security incidents. 
  • Threat Intelligence Utilization: Integrate active cyber threat intelligence (CTI) feeds and Indicators of Compromise (IoCs) into ongoing investigations to identify sophisticated threat actor campaigns. 
  • Rule Tuning & Optimization: Analyze alert queues to identify false-positive trends and collaborate with Tier 3 engineers to recommend precise logic modifications for SIEM correlation rules and EDR policies. 
  • Runbook Maintenance: Author, refine, and maintain Standard Operating Procedures (SOPs) and incident response runbooks to reflect evolving adversary tactics and techniques. 
  • Maintain accurate records of incidents, investigations, and security-related activities within the incident management platform. 
  • Create detailed reports on security incidents, response actions taken, and recommendations for improvement. 
  • Research new concepts and present them to the internal team as well as customers. 

What Do We Expect?

  • Technical Domain Expertise: Strong technical competency in network traffic analysis, log management architecture, endpoint forensics, and parsing diverse event logs across Windows, Linux, and enterprise cloud environments. 
  • Framework Proficiency: Proven experience utilizing defensive frameworks specifically the MITRE ATT&CK matrix and the Cyber Kill Chain to map, trace, and document malicious adversary behavior. 
  • Analytical Skills: Highly developed analytical mindset with the ability to dissect complex log data, analyze suspicious email artifacts, and interpret endpoint telemetry under operational time constraints. 
  • Excellent English written and verbal communication skills. 
  • Prior experience working within a 24x7 Security Operations Centre (SOC). Readiness to fulfill on-call roles 
  • Security monitoring experience with one or more SIEM technologies, preferably Microsoft Sentinel. 
  • Knowledge of EDR solutions including Microsoft Defender 
  • Basic understanding of Windows, Linux and cloud technologies including Microsoft Azure and Office365. 
  • Good understanding of security solutions including SIEMs, Web Proxies, Anti-Virus, Firewalls, VPN, authentication providers and mechanisms, encryption, IPS/IDS. 
  • Basic understanding of networking principles including TCP/IP, WANs, LANs, and commonly used Internet protocols. 

Nice to have (big advantage):

  • Active Certifications: GIAC Certified Incident Handler (GCIH), CompTIA Cybersecurity Analyst (CySA+), Cisco CyberOps Professional, or Blue Team Level 2 (BTL2). 
  • Automation & Scripting: Foundational scripting capabilities (Python, Bash, or PowerShell) to assist in automating repetitive data-gathering or log-parsing tasks. 
  • Cloud Ecosystems: Hands-on familiarity with native monitoring, logging, and security suites within enterprise cloud environments (AWS, Microsoft Azure, or GCP). 

Why Join Us?

  • Competitive remunerations and benefits package
  • Opportunity to grow your career and get exposure to international brands, working on complex multi-technology projects
  • Friendly, yet competitive work environment where everyone’s success is celebrated
  • Flexible working hours/working location

Skills Required

  • Strong technical competency in network traffic analysis, log management architecture, and endpoint forensics across Windows, Linux, and cloud environments
  • Proven experience using defensive frameworks such as MITRE ATT&CK and the Cyber Kill Chain
  • Experience in a 24x7 Security Operations Centre and readiness to fulfill on-call roles
  • Security monitoring experience with SIEM technologies, preferably Microsoft Sentinel
  • Knowledge of EDR solutions including Microsoft Defender
  • Basic understanding of Windows, Linux and cloud technologies including Microsoft Azure and Office365
  • Good understanding of security solutions: SIEMs, Web Proxies, Anti-Virus, Firewalls, VPN, authentication mechanisms, encryption, IPS/IDS
  • Basic understanding of networking principles including TCP/IP, WANs, LANs and common internet protocols
  • Highly developed analytical skills and ability to analyze complex log data and endpoint telemetry under time constraints
  • Excellent written and verbal English communication skills
  • Active certifications (GCIH, CySA+, Cisco CyberOps Professional, or BTL2)
  • Foundational scripting capabilities (Python, Bash, or PowerShell) for automation and log parsing
  • Hands-on familiarity with cloud monitoring and security suites in AWS, Azure, or GCP
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Gilbert, Arizona
96 Employees
Year Founded: 2019

What We Do

AIOPSGROUP, a valantic company is a forward-thinking digital powerhouse operating at the nexus of eCommerce, Data, and Technology, with a strong commitment to digital accessibility. Our holistic approach encompasses innovative solutions that drive business growth and operational efficiency for our clients, spanning across various industries. Understanding the significance of inclusivity in today's digital landscape, we prioritize making digital content and services accessible to all users, including those with disabilities. By integrating accessibility standards into our eCommerce platforms, data analysis tools, and technology solutions, we aim to foster an inclusive digital environment. This commitment not only aligns with our core values but also ensures compliance with the latest digital accessibility regulations, providing a seamless, user-friendly experience for every customer. At AIOPSGROUP, a valantic company we believe in leveraging technology to break down barriers and create equal opportunities for everyone in the digital world. We are proud to serve some of the leading brands such as Puma, Mark Jacobs, Coach, Stuart Weitzman, Kate Spade, Carter's, Acne Studios, IKEA, s. Oliver, Fjallraven, MCM, Rossignol, and Fenix Outdoor.

Similar Jobs

Pfizer Logo Pfizer

Platform Engineer

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
36 Locations
121990 Employees
65K-109K Annually

DraftKings Logo DraftKings

Software Architect

Digital Media • Gaming • Information Technology • Software • Sports • Esports • Big Data Analytics
Remote or Hybrid
Sofia, Sofia-grad, BGR
6400 Employees

DraftKings Logo DraftKings

Software Architect

Digital Media • Gaming • Information Technology • Software • Sports • Esports • Big Data Analytics
Remote or Hybrid
Bulgaria
6400 Employees
8-8 Annually

Pfizer Logo Pfizer

Investigator Contracts Lead, Sr. Manager

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Remote
27 Locations
121990 Employees
250K-250K Annually

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account