SOC Lead Incident Responder - Confidential

Insight Global
Medford, OR, United States
25 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Microsoft Azure BASIC (Programming Language) CompTIA Security+ Log Analysis Microsoft Security Essentials Azure Active Directory Kusto Query Language Security Information and Event Management Mitre Att&ck Microsoft Sentinel

Job description

The SOC Lead Incident Responder (Tier 1) serves as the primary point of contact for security alerts and is responsible for triaging, investigating, and leading the response to cybersecurity incidents as part of the SOC team. This is a hands-on technical role focused on rapid detection and containment using the organization’s Microsoft security stack. While not a people-management position, the responder takes the lead on coordinating incident response activities and guiding fellow analysts through the response process.

Requirements

  • Hands-on experience with Microsoft Sentinel (Azure SIEM): alert triage, investigation, and basic KQL queries.

  • Proficiency with Microsoft Defender (EDR): endpoint investigation, alert analysis, and containment actions.

  • Working knowledge of Microsoft Entra ID: identity protection, sign-in log analysis, and conditional access concepts.

  • Solid understanding of incident response fundamentals (detection, triage, containment, eradication, recovery, lessons learned).

  • Familiarity with common attack techniques and frameworks (e.g., MITRE ATT&CK).

  • Strong analytical, communication, and documentation skills.

  • Ability to remain calm and lead under pressure during active incidents. * Relevant certifications such as SC-200, AZ-500, CompTIA Security+, or equivalent.

  • Prior experience in a SOC or incident response environment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea Ā· World Congress 2022

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber Ā· World Congress 2026 Europe

11:18 min

Addressing audience questions on security and microservice architectures

Reinhard Kugler Ā· LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler Ā· LIVE

5:01 min

Container hosting options available on Microsoft Azure

Federico Fregosi Ā· World Congress 2022

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn Ā· LIVE

Videos

See all

Related articles

See all