Job Description & Details
This is a hands-on Tier 3 SOC role where you will be knee-deep in active forensic investigations, malware triage, and threat hunting rather than just staring at alert dashboards all day. If you enjoy digging into compromised systems to figure out how an attacker breached the perimeter and writing up root cause analyses, this gig gives you the autonomy to actually make a security impact.
What You'll Actually Be Doing
Your day-to-day will revolve around leading incident response efforts, picking apart malicious payloads, and tuning detection rules so the team stops chasing false positives. You will spend a good chunk of your time correlating threat intelligence, building custom signatures, and proactively hunting for advanced adversaries hiding in the network. Expect to also mentor junior analysts on SIEM tools like Microsoft Sentinel and occasionally jump on after-hours calls when critical incidents pop off.
The Core Tech Stack
You are going to need deep, production-level familiarity with SIEM platforms—specifically Microsoft Sentinel—alongside solid digital forensics and incident response (DFIR) frameworks. Knowing your way around malware analysis techniques, attacker tooling, and writing custom detection signatures is non-negotiable here since you will be building the rules and leading the root cause investigations.
Interview Expectations
The hiring team is going to test your deep technical chops, likely asking you to walk them through a complex forensic investigation from initial indicator of compromise to final scope-of-impact report. Be prepared for a scenario where they drop a hypothetical malware execution in your lap and ask you to explain your triage steps and how you would build a custom detection rule for it in Sentinel. They want to see that you stay calm under pressure and have a methodical approach to threat containment.
Application Advice
Skip the generic cybersecurity buzzwords on your resume and focus heavily on your direct experience with forensic investigations, malware triage, and SIEM tuning. Explicitly mention Microsoft Sentinel, custom detection engineering, and any threat hunting frameworks you have used in past roles so you easily clear the ATS filters. Highlight times you acted as an escalation point or technical leader for Tier 1 and Tier 2 analysts.