
L1 SOC Analyst
Posted 21 hours ago

Posted 21 hours ago
This is a fully remote position, open to applicants in Georgia.
• Oversee and prioritize incidents in Microsoft Sentinel and Microsoft Defender XDR based on severity.
• Assess alerts to determine if they are true positives, false positives, or benign, and document the reasoning.
• Examine Defender for Office 365 quarantine and manage user-reported phishing incidents.
• Make decisions to either release or block quarantined content.
• Analyze message headers, SPF/DKIM/DMARC results, URLs, and attachments.
• Execute pre-built KQL queries in Advanced Hunting to identify impacted users and assets.
• Implement runbook-defined containment measures, such as revoking sessions, blocking sign-ins, isolating devices, and purging delivered messages.
• Escalate issues that exceed the mandate, providing timelines, evidence, and actions taken.
• Maintain audit-ready case records and ensure smooth shift transitions.
• Identify frequent detections and recurring false positives for optimization.
• Collaborate with the Cloud Security Engineer in a Microsoft-based environment.
• Progress from L1 triage to L2 analysis.
• Minimum of 1 year in IT support, service desk, systems administration, or a security operations role.
• Strong candidates with relevant certifications and demonstrable lab work may be considered even without commercial security experience.
• Proficient understanding of Microsoft 365 and either a cloud-first or hybrid environment.
• Knowledge of networking and mail flow fundamentals: TCP/IP, DNS, SMTP, MX records, VPN, and firewall concepts.
• Basic understanding of Windows and macOS fundamentals, including processes, logons, and log locations.
• Familiarity with common attack techniques: phishing, credential theft, MFA fatigue, token theft, and malware delivery.
• Proficient in written and spoken English.
• Ability to write case notes and escalations in English.
• Discipline to adhere strictly to a runbook and the judgment to escalate promptly rather than improvise.
• Hands-on experience with Microsoft Sentinel, Defender XDR, Defender for Office 365, or Entra ID.
• Capability to read and modify a KQL query or utilize basic PowerShell.
• CompTIA Security+ or Microsoft SC-900 certification preferred.
• Familiarity with MITRE ATT&CK framework.
• Awareness of NIST SP 800-171, CMMC 2.0, or GDPR regulations.
• Funded Microsoft certification pathway, with the SC-200 exam costs covered by KVG.
• Clearly defined progression path from L1 triage to L2 analysis.
• Direct mentoring provided by the Cloud Security Engineer.
• Coverage during European business hours with rotational extended-hours support for other regions.
• Exposure to a single-vendor Microsoft security stack: Sentinel, Defender XDR, Entra ID, Intune, and Purview.
Concentric
Samsara
Axians Somnitec AG
Get handpicked remote jobs straight to your inbox weekly.