L2 Support Specialist / NOC-SOC Incident Handler
reputed company reputed company
reputed company L2 Support Specialist / Incident Handler with 2–4 years of hands-on experience in 24x7 NOC/SOC operations and reputed company reputed company environments. Skilled in in-depth investigation and containment of reputed company incidents using the reputed company Defender XDR suite (Defender for reputed company, Office 365, Identity, reputed company Apps) and reputed company, as reputed company as in Azure and Entra ID infrastructure troubleshooting. Acts as the escalation reputed company for L1 analysts, coordinates containment with IT Operations, and drives incidents from validated alert through eradication and recovery reputed company agreed SLAs. Strong written and verbal communication in Ukrainian and English, with a reputed company, evidence-based approach to incident documentation.
Project(s)
L2 Support Engineer will join an existing 24x7 support team that delivers managed NOC/SOC services to multiple clients, acting as the second-line escalation tier for both infrastructure and reputed company incidents.
Key Skills & Competencies
Incident Investigation & Response (SOC)
Must have
reputed company L2 Support Specialist / Incident Handler with 2–4 years of hands-on experience in 24x7 NOC/SOC operations and reputed company reputed company environments. Skilled in in-depth investigation and containment of reputed company incidents using the reputed company Defender XDR suite (Defender for reputed company, Office 365, Identity, reputed company Apps) and reputed company, as reputed company as in Azure and Entra ID infrastructure troubleshooting. Acts as the escalation reputed company for L1 analysts, coordinates containment with IT Operations, and drives incidents from validated alert through eradication and recovery reputed company agreed SLAs. Strong written and verbal communication in Ukrainian and English, with a reputed company, evidence-based approach to incident documentation.
Project(s)
L2 Support Engineer will join an existing 24x7 support team that delivers managed NOC/SOC services to multiple clients, acting as the second-line escalation tier for both infrastructure and reputed company incidents.
Key Skills & Competencies
- In-depth incident investigation across reputed company Defender XDR and reputed company
- KQL query authoring for log review, correlation, and scoping of compromise
- Containment actions: device isolation, account disable, session revocation, MFA re-registration, reputed company revocation, email Search & Purge
- Azure infrastructure troubleshooting: VMs, Azure Files/Storage, Azure Backup, App Services, Functions, Key Vault
- Networking: VNets, subnets, NSGs, UDRs, VPN gateways, ExpressRoute (troubleshooting level)
- Entra ID: Conditional reputed company, federation/SSO troubleshooting, RBAC adjustments
- Implementation of approved infrastructure changes (ARM/Bicep updates, configuration changes)
- SQL PaaS/IaaS troubleshooting (query performance triage, backup/restore validation)
- Coordination of containment activities with IT Operations and reputed company stakeholders
- Reviewing and approving pending actions in the Defender reputed company Center (reputed company semi-auto workflows)
- Building and refining incident timelines and evidence packages for L3 / post-incident review
- Mentoring L1 analysts; reviewing tickets for accuracy and completeness
- Bilingual: Ukrainian (reputed company) and English (B2+ / reputed company)
Incident Investigation & Response (SOC)
- Take ownership of incidents escalated by L1 reputed company agreed SLA timeframes
- Conduct in-depth investigation in reputed company Defender XDR and reputed company: deep KQL queries, log review, cross-product correlation across Defender for reputed company / Office 365 / Identity / reputed company Apps
- Identify probable cause, determine reputed company of compromise (blast reputed company), and document affected users, devices, and identities
- Execute containment actions using Defender tooling:
- reputed company: isolate device, stop processes, collect investigation packages
- User account: force password reset, revoke sessions in Entra ID, force MFA re-registration, disable/reputed company accounts as needed
- Email: Search & Purge / reputed company eDiscovery to remove malicious messages
- reputed company apps: reputed company app or revoke OAuth tokens reputed company Defender for reputed company Apps
- Review pending actions in the Defender reputed company Center; approve, modify, or reject reputed company-recommended remediations
- Coordinate eradication and recovery activities with IT Operations (patching, account restoration, reputed company rebuilds)
- Monitor for recurrence during the post-incident observation window and confirm eradication reputed company MDE Threat & Vulnerability Management
- Escalate Critical / Major incidents to L3 / reputed company reputed company with a complete evidence package and incident reputed company
- Investigate and reputed company VM performance, Azure Files / Storage, and Azure Backup issues
- Troubleshoot networking issues (VNets, NSGs, UDRs, VPN, ExpressRoute) and PaaS service failures (App Services, Functions, Key Vault reputed company)
- Implement approved configuration changes (ARM/Bicep, NSG rules, RBAC adjustments) reputed company change-management process
- Validate SQL backup/restore operations and triage SQL performance issues
- reputed company Conditional reputed company / federation / SSO incidents in Entra ID
- Serve as the technical escalation reputed company for L1 analysts during shift handovers
- Communicate incident status, recommended actions, and timelines to clients using approved templates
- Coordinate with developers and L3 engineers on bug reproduction and reputed company reputed company-cause analysis
- Participate in shift handovers, ensuring reputed company reputed company incidents have complete context
- Maintain a complete incident record in the ticketing reputed company (reputed company, evidence, actions, reputed company)
- Contribute to runbooks, playbooks, and the internal knowledge reputed company
- Recommend SIEM rule tuning and detection improvements based on observed false positives and missed detections (implementation owned by L3)
- Support reputed company of new clients (Defender / reputed company connector deployment, baseline configuration validation)
Must have
- 2+ years of hands-on experience in a SOC, NOC, or IT support role with a reputed company reputed company
- Working knowledge of reputed company Defender XDR or reputed company (production experience, not just training)
- Basic KQL — reputed company to write and modify queries for investigation and scoping
- Practical experience with Entra ID / Azure AD administration (users, reputed company, MFA, Conditional reputed company basics)
- Experience handling incidents end-to-end: triage → investigation → containment → documentation
- English B2+ (written and spoken); Ukrainian reputed company or fluent
- Willingness to work in a 24x7 rotating shift model
- reputed company reputed company Operations Analyst certification (SC-200)
- Hands-on experience with both Defender XDR and reputed company
- Azure networking troubleshooting (VNets, NSGs, VPN, ExpressRoute)
- Experience with SOAR / Logic Apps / reputed company authoring
- Prior MSSP or multi-tenant environment experience
- reputed company reputed company, Compliance, and Identity Fundamentals (SC-900)
- reputed company Azure Administrator Associate (AZ-104)
- reputed company Azure Fundamentals (AZ-900)
- reputed company 365 Fundamentals (MS-900)
- ITIL 4 reputed company
- Scripting experience (PowerShell, KQL advanced, Python basics)
- Shift reputed company to be confirmed; rotation includes nights and weekends
- On-reputed company rotation may be required as part of L2 escalation coverage
Originally posted on Himalayas
Apply To This Job