Security Operations Analyst - SOC - (L2) - Banking Project

PT Aktualisasi Gratia Talenta IndonesiaJakarta Pusat, DKI Jakartaglintsavaldatud 03.09.2026
Nõutav:AzureCloudSecurity

Key Responsibilities:

  • Provide L2 security operations support for Microsoft Defender for Endpoint, Microsoft Defender for Cloud Apps, and Microsoft Purview.
  • Monitor, review, and perform initial triage of security alerts, incidents, requests, and customer tickets.
  • Perform initial investigation of MDE alerts, incidents, device timelines, antivirus detections, device health, onboarding status, sensor health, and endpoint policies.
  • Review and investigate MDCA alerts, user activities, connected applications, cloud discovery information, activity policies, anomaly detections, and connector status.
  • Review Microsoft Purview alerts and events related to Information Protection, sensitivity labels, Data Loss Prevention (DLP), Endpoint DLP, Insider Risk Management, and Data Lifecycle Management.
  • Assess alert severity, potential user impact, available evidence, and required next steps based on approved procedures.
  • Collect and document relevant logs, screenshots, diagnostic packages, alert details, audit records, policy status, connector status, and investigation evidence.
  • Perform basic troubleshooting using approved runbooks, knowledge articles, SOPs, and support procedures.
  • Manage and update customer tickets through ServiceNow (SNOW), ensuring accurate categorisation, prioritisation, investigation notes, evidence, customer updates, and closure information.
  • Escalate unresolved, high-impact, or complex security issues to L2/L3, platform SMEs, Microsoft Support, or relevant client technical teams.
  • Coordinate with Endpoint, Intune, Identity, Compliance, Infrastructure, and Operations teams when required.
  • Maintain accurate documentation and ensure all incidents and requests are handled within agreed SLA and operational procedures.
  • Support continuous improvement by identifying recurring issues and providing feedback on runbooks and knowledge articles.

Requirements:

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or a related field is preferred.
  • Equivalent practical experience in cybersecurity, Microsoft security operations, or IT support may also be considered.
  • 3–5 years of experience in SOC, cybersecurity operations, security support, service desk, endpoint support, or Microsoft 365 operational support.
  • Working knowledge of Microsoft Defender for Endpoint (MDE) and the Microsoft Defender portal.
  • Working knowledge of Microsoft Defender for Cloud Apps (MDCA) and cloud security monitoring.
  • Ability to perform basic investigation and triage of security alerts and incidents.
  • Understanding of endpoint health, device onboarding, antivirus detections, device timelines, and security policy status.
  • Familiarity with cloud application activities, connected applications, cloud discovery, anomaly detection, and security policies.

Preferred Certifications:

  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • Microsoft Certified: Endpoint Administrator Associate (MD-102)
  • Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)
  • Microsoft Certified: Information Security Administrator Associate (SC-401)
  • Microsoft Certified: Azure Security Engineer Associate (AZ-500)
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300)

Skills: Penetration Testing, Certified Information Security Manager (CISM), Information Security, Cybersecurity, Network Security