SOC Lead Incident Responder - Confidential
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
The SOC Lead Incident Responder (Tier 1) serves as the primary point of contact for security alerts and is responsible for triaging, investigating, and leading the response to cybersecurity incidents as part of the SOC team. This is a hands-on technical role focused on rapid detection and containment using the organizationās Microsoft security stack. While not a people-management position, the responder takes the lead on coordinating incident response activities and guiding fellow analysts through the response process.
Requirements
-
Hands-on experience with Microsoft Sentinel (Azure SIEM): alert triage, investigation, and basic KQL queries.
-
Proficiency with Microsoft Defender (EDR): endpoint investigation, alert analysis, and containment actions.
-
Working knowledge of Microsoft Entra ID: identity protection, sign-in log analysis, and conditional access concepts.
-
Solid understanding of incident response fundamentals (detection, triage, containment, eradication, recovery, lessons learned).
-
Familiarity with common attack techniques and frameworks (e.g., MITRE ATT&CK).
-
Strong analytical, communication, and documentation skills.
-
Ability to remain calm and lead under pressure during active incidents. * Relevant certifications such as SC-200, AZ-500, CompTIA Security+, or equivalent.
-
Prior experience in a SOC or incident response environment.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.juju.comGood distractions
Talks and stories from around this role ā technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Walking Into The Era of Supply Chain Risks
Dev Digest 191: Malware interviews, EU ā¤ļø Open Source and Skilled Agents