All jobs
Remote

L2 Support Specialist / NOC-SOC Incident Handler

REW Technology

The role

Job description

Professional Summary
Experienced L2 Support Specialist / Incident Handler with 2–4 years of hands-on experience in 24x7 NOC/SOC operations and Microsoft cloud environments. Skilled in in-depth investigation and containment of security incidents using the Microsoft Defender XDR suite (Defender for Endpoint, Office 365, Identity, Cloud Apps) and Microsoft Sentinel, as well as in Azure and Entra ID infrastructure troubleshooting. Acts as the escalation point for L1 analysts, coordinates containment with IT Operations, and drives incidents from validated alert through eradication and recovery within agreed SLAs. Strong written and verbal communication in Ukrainian and English, with a structured, evidence-based approach to incident documentation.

Project(s)
L2 Support Engineer will join an existing 24x7 support team that delivers managed NOC/SOC services to multiple clients, acting as the second-line escalation tier for both infrastructure and security incidents.

Key Skills & Competencies
  • In-depth incident investigation across Microsoft Defender XDR and Microsoft Sentinel
  • KQL query authoring for log review, correlation, and scoping of compromise
  • Containment actions: device isolation, account disable, session revocation, MFA re-registration, token revocation, email Search & Purge
  • Azure infrastructure troubleshooting: VMs, Azure Files/Storage, Azure Backup, App Services, Functions, Key Vault
  • Networking: VNets, subnets, NSGs, UDRs, VPN gateways, ExpressRoute (troubleshooting level)
  • Entra ID: Conditional Access, federation/SSO troubleshooting, RBAC adjustments
  • Implementation of approved infrastructure changes (ARM/Bicep updates, configuration changes)
  • SQL PaaS/IaaS troubleshooting (query performance triage, backup/restore validation)
  • Coordination of containment activities with IT Operations and client stakeholders
  • Reviewing and approving pending actions in the Defender Action Center (AIR semi-auto workflows)
  • Building and refining incident timelines and evidence packages for L3 / post-incident review
  • Mentoring L1 analysts; reviewing tickets for accuracy and completeness
  • Bilingual: Ukrainian (native) and English (B2+ / C1)
Responsibilities Handled
Incident Investigation & Response (SOC)
  • Take ownership of incidents escalated by L1 within agreed SLA timeframes
  • Conduct in-depth investigation in Microsoft Defender XDR and Microsoft Sentinel: deep KQL queries, log review, cross-product correlation across Defender for Endpoint / Office 365 / Identity / Cloud Apps
  • Identify probable cause, determine scope of compromise (blast radius), and document affected users, devices, and identities
  • Execute containment actions using Defender tooling:
  • Endpoint: isolate device, stop processes, collect investigation packages
  • User account: force password reset, revoke sessions in Entra ID, force MFA re-registration, disable/block accounts as needed
  • Email: Search & Purge / Purview eDiscovery to remove malicious messages
  • Cloud apps: block app or revoke OAuth tokens via Defender for Cloud Apps
  • Review pending actions in the Defender Action Center; approve, modify, or reject AIR-recommended remediations
  • Coordinate eradication and recovery activities with IT Operations (patching, account restoration, system rebuilds)
  • Monitor for recurrence during the post-incident observation window and confirm eradication via MDE Threat & Vulnerability Management
  • Escalate Critical / Major incidents to L3 / Security Lead with a complete evidence package and incident timeline
Infrastructure Support (NOC)
  • Investigate and resolve VM performance, Azure Files / Storage, and Azure Backup issues
  • Troubleshoot networking issues (VNets, NSGs, UDRs, VPN, ExpressRoute) and PaaS service failures (App Services, Functions, Key Vault access)
  • Implement approved configuration changes (ARM/Bicep, NSG rules, RBAC adjustments) within change-management process
  • Validate SQL backup/restore operations and triage SQL performance issues
  • Resolve Conditional Access / federation / SSO incidents in Entra ID
Client & Internal Coordination
  • Serve as the technical escalation point for L1 analysts during shift handovers
  • Communicate incident status, recommended actions, and timelines to clients using approved templates
  • Coordinate with developers and L3 engineers on bug reproduction and complex root-cause analysis
  • Participate in shift handovers, ensuring all open incidents have complete context
Documentation & Continuous Improvement
  • Maintain a complete incident record in the ticketing system (timeline, evidence, actions, outcomes)
  • Contribute to runbooks, playbooks, and the internal knowledge base
  • Recommend SIEM rule tuning and detection improvements based on observed false positives and missed detections (implementation owned by L3)
  • Support onboarding of new clients (Defender / Sentinel connector deployment, baseline configuration validation)
Requirements
Must have
  • 2+ years of hands-on experience in a SOC, NOC, or IT support role with a security focus
  • Working knowledge of Microsoft Defender XDR or Microsoft Sentinel (production experience, not just training)
  • Basic KQL — able to write and modify queries for investigation and scoping
  • Practical experience with Entra ID / Azure AD administration (users, groups, MFA, Conditional Access basics)
  • Experience handling incidents end-to-end: triage → investigation → containment → documentation
  • English B2+ (written and spoken); Ukrainian native or fluent
  • Willingness to work in a 24x7 rotating shift model
Strong plus
  • Microsoft Security Operations Analyst certification (SC-200)
  • Hands-on experience with both Defender XDR and Sentinel
  • Azure networking troubleshooting (VNets, NSGs, VPN, ExpressRoute)
  • Experience with SOAR / Logic Apps / playbook authoring
  • Prior MSSP or multi-tenant environment experience
Nice to have
  • Microsoft Security, Compliance, and Identity Fundamentals (SC-900)
  • Microsoft Azure Administrator Associate (AZ-104)
  • Microsoft Azure Fundamentals (AZ-900)
  • Microsoft 365 Fundamentals (MS-900)
  • ITIL 4 Foundation
  • Scripting experience (PowerShell, KQL advanced, Python basics)
Availability
  • Shift pattern to be confirmed; rotation includes nights and weekends
  • On-call rotation may be required as part of L2 escalation coverage

Originally posted on Himalayas

Keep exploring