SOC Analyst Level 2 (Microsoft Security Stack)
Kloudynet · Federal Territory of Kuala Lumpur, Malaysia
Apply & track with Apply EdgeRole Overview:We are looking for a SOC Analyst to join our Managed Security Operations team and work extensively with the Microsoft Security ecosystem. The analyst will be responsible for monitoring, investigating, triaging and responding to security incidents across customer environments using Microsoft Sentinel, Microsoft Defender and related security technologies.The ideal candidate should have strong hands-on experience in SIEM monitoring, incident investigation, threat hunting, KQL and Microsoft security technologies, with the ability to distinguish genuine threats from false positives and drive incidents through to resolution.
Key Responsibilities
L2/L3 SOC Engineer Responsibilities:Monitor security alerts and incidents across Microsoft Sentinel and Microsoft Defender.Perform L1/L2 security alert triage, investigation and escalation.Investigate incidents using: Microsoft Sentinel Microsoft Defender XDR Microsoft Defender for Endpoint (MDE) Microsoft Defender for Office 365 Microsoft Defender for Cloud Microsoft Entra ID Microsoft Defender for Cloud AppsDevelop and use KQL queries for investigation, detection and threat hunting.Analyse endpoint, identity, email, cloud, authentication and network telemetry.Investigate suspicious: Process execution PowerShell activity Authentication anomalies Account compromise Malware and ransomware Phishing and Business Email Compromise Impossible travel / risky sign-ins Privilege escalation Data exfiltrationPerform threat hunting across Microsoft security telemetry.Analyse Indicators of Compromise (IOCs), including IP addresses, domains, URLs, hashes and suspicious accounts.Correlate events across multiple data sources to reconstruct attack timelines.Execute approved incident-response actions such as endpoint isolation, account containment and indicator blocking.Maintain accurate incident documentation and investigation timelines.Escalate complex incidents to L2/L3, Detection Engineering or Incident Response teams.Tune and improve Sentinel analytics rules, queries and automation based on observed threats.Support development and maintenance of Sentinel playbooks, automation rules and detection content.Prepare daily, weekly and monthly SOC reports.Participate in shift handovers and maintain proper SOC operational procedures.Required Technical SkillsMicrosoft SecurityStrong practical knowledge of:Microsoft SentinelMicrosoft Defender XDRMicrosoft Defender for EndpointMicrosoft Defender for Office 365Microsoft Defender for CloudMicrosoft Entra IDMicrosoft Defender for Cloud AppsMicrosoft Purview / Information ProtectionSIEM & InvestigationAdvanced KQLSIEM alert investigationIncident correlationThreat huntingMITRE ATT&CK mappingIOC investigationMalware analysis fundamentalsWindows security eventsAuthentication and identity logsNetwork and firewall logsIncident ResponseAlert triageIncident containmentEndpoint investigationPhishing investigationAccount compromise investigationMalware/ransomware investigationRoot-cause analysisEvidence preservationIncident documentationCertifications:Candidates should hold at least any TWO of the following certifications:CompTIA Cybersecurity Analyst+ (CySA+)EC-Council Certified Incident Handler (ECIH)ISC2 Certified in Cybersecurity (CC)ISC2 Systems Security Certified Practitioner (SSCP)Certified Information Systems Security Professional (CISSP)Certified Information Security Manager (CISM)GIAC Security Operations Certification (GSOC)OffSec Defense Analyst (OSDA)CREST Accredited SOC ProviderEC-Council SOC AnalystGlobal ACE Certified Security Operations Centre Analyst (CSOC)Cloud Security Alliance Certificate of Cloud Security Knowledge (CCSK)OffSec Incident Response (OSIR)Preferred Certification CombinationAny 2 certifications, with preference for:CompTIA CySA+ + EC-Council Certified Incident Handler (ECIH)This combination aligns particularly well with the role's requirements around SOC monitoring, security analysis, incident investigation and response.
Qualifications
Bachelor's degree in Cybersecurity, Information Technology, Computer Science or a related field preferred.2–5 years of experience in a SOC/MSSP environment.Hands-on experience with Microsoft Sentinel and Microsoft Defender technologies.Experience working in a 24×7 SOC / shift-based environment is preferred.Strong understanding of the MITRE ATT&CK framework.Experience with KQL-based security investigations is required.Key Performance Expectations:The successful candidate should be able to:Detect → Triage → Investigate → Correlate → Contain → Escalate → DocumentThe role requires strong analytical thinking, attention to detail, disciplined incident handling and the ability to work effectively under time-sensitive SOC conditions.Core Competencies:Security monitoringIncident responseThreat huntingKQLMicrosoft SentinelMicrosoft DefenderMITRE ATT&CKDigital investigationAnalytical thinkingClear technical communicationSOC process disciplineShift and handover management