Live opening · Posted 3 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Company Description
SOCRoom by Procain consulting, helps businesses strengthen security operations with continuous monitoring, faster response, and expert SOC support.
We work with organisations that need better visibility, alert handling, incident response, and security operations coverage without building a full SOC in-house.
Our services include Managed SOC, SOC as a Service, SOC Staff Augmentation, Cloud Security Monitoring, threat detection, alert triage, and incident response support.
Built on the principle of Detect. Prevent. Prevail., SOCRoom by Procain consulting, helps teams move from security alerts to real action - faster, sharper, and with greater operational confidence.
Key responsibilities
Team leadership and shift operations
Lead, mentor and schedule a team of L1/L2 analysts to maintain 24x7 coverage and consistent
service quality.
Own shift handovers, ensuring every open incident transfers with current status, next action and
owner.
Conduct quality reviews of closed incidents, verifying verdicts (true positive, benign positive,
false positive) and documentation.
Coach analysts on investigation methodology, KQL and tooling; drive onboarding and structured
skills development.
Incident detection and response
Act as the escalation point for high-severity incidents, including lateral movement, privileged
account compromise and data exfiltration.
Direct investigations from initial alert through entity analysis, timeline reconstruction,
containment and closure.
Coordinate containment actions with customer IT and security teams, and with L3 / incident
response specialists where needed.
Lead post-incident reviews and translate lessons learned into detection and process
improvements.
Microsoft Sentinel platform ownership
Oversee analytics rule lifecycle: design, testing, tuning, alert grouping, suppression and
retirement of noisy rules.
Develop and review KQL queries, hunting queries, workbooks and watchlists.
Guide automation using playbooks (Logic Apps) and automation rules to reduce manual triage
effort.
Work with engineering teams on data connector onboarding, log source health and ingestion
cost optimization.
Wazuh operations (where deployed)
Supervise monitoring of Wazuh-managed customer environments, including agent health, rule
and decoder tuning, and alert triage.
Support integration of Wazuh alerts into central SOC workflows and ticketing.
Customer engagement and reporting
Serve as a technical point of contact for customers during incidents and in regular service
reviews.
Produce monthly SOC reports covering incident trends, SLA performance, detection coverage
and recommendations.
Ensure adherence to contractual SLAs for time-to-triage, time-to-escalate and time-to-notify.
Maintain and improve runbooks, escalation matrices and standard operating procedures.
Required qualifications (mandatory)
Bachelor's degree in Computer Science, Information Security or a related field, or equivalent professional experience.
5+ years of experience in a SOC, MSSP or MDR environment, including at least 1–2 years leading or mentoring analysts.
Hands-on experience with Microsoft Sentinel (minimum 2 years in production), covering analytics rules, incidents, entity investigation, workbooks, watchlists, UEBA and playbooks.
Strong proficiency in KQL for detection engineering, threat hunting and investigation.
Working knowledge of the Microsoft security ecosystem: Defender XDR (Endpoint, Identity, Office 365, Cloud Apps), Entra ID and Azure activity logs.
Solid understanding of the incident response lifecycle, the MITRE ATT&CK framework and common attack techniques.
Good knowledge of networking, Windows and Linux internals, Active Directory and cloud security fundamentals.
Experience working to customer SLAs in a multi-tenant or managed services environment.
Excellent written and verbal communication skills, including incident reporting to technical and executive audiences.
Willingness to work in a 24x7 rotational environment and to be available for on-call escalations.
Preferred qualifications
Hands-on experience with Wazuh: agent deployment, custom rules and decoders, active response, file integrity monitoring and vulnerability detection.
Microsoft certifications such as SC-200 (Security Operations Analyst), AZ-500 or SC-100.
Industry certifications such as GCIH, GCIA, CySA+, BTL1/BTL2, or equivalent incident response credentials.
Experience with other SIEM/SOAR platforms (Splunk, QRadar, Elastic) and EDR tools (CrowdStrike, SentinelOne).
Scripting skills in PowerShell or Python for automation and enrichment.
Exposure to threat intelligence platforms, threat hunting programs and detection-as-code practices.
Familiarity with compliance frameworks such as ISO 27001, SOC 2, PCI DSS or NIST CSF.
Key competencies
Leadership: builds a motivated, accountable team and develops analysts into senior contributors.
Analytical judgment: makes sound, timely decisions under pressure with incomplete information.
Customer focus: communicates clearly and calmly with customers during active incidents.
Continuous improvement: uses data to reduce false positives, improve detection coverage and streamline workflows.
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.