Tech Stack
Job Description, Responsibilities & Requirements
About the Position
Join Our Team at REW Technology
We are seeking an experienced L2 Support Specialist / NOC-SOC Incident Handler with 2–4 years of hands-on experience in 24x7 NOC/SOC operations and Microsoft cloud environments. This role involves in-depth investigation and containment of security incidents using the Microsoft Defender XDR suite (Defender for Endpoint, Office 365, Identity, Cloud Apps) and Microsoft Sentinel, as well as Azure and Entra ID infrastructure troubleshooting. You will act as the escalation point for L1 analysts, coordinate containment with IT Operations, and drive incidents from validated alert through eradication and recovery within agreed SLAs. Strong written and verbal communication in Ukrainian and English is required, along with a structured, evidence-based approach to incident documentation.
Responsibilities
Incident Investigation & Response (SOC)
- Take ownership of incidents escalated by L1 within agreed SLA timeframes
- Conduct in-depth investigation in Microsoft Defender XDR and Microsoft Sentinel: deep KQL queries, log review, cross-product correlation across Defender for Endpoint / Office 365 / Identity / Cloud Apps
- Identify probable cause, determine scope of compromise (blast radius), and document affected users, devices, and identities
- Execute containment actions using Defender tooling:
- Endpoint: isolate device, stop processes, collect investigation packages
- User account: force password reset, revoke sessions in Entra ID, force MFA re-registration, disable/block accounts as needed
- Email: Search & Purge / Purview eDiscovery to remove malicious messages
- Cloud apps: block app or revoke OAuth tokens via Defender for Cloud Apps
- Review pending actions in the Defender Action Center; approve, modify, or reject AIR-recommended remediations
- Coordinate eradication and recovery activities with IT Operations (patching, account restoration, system rebuilds)
- Monitor for recurrence during the post-incident observation window and confirm eradication via MDE Threat & Vulnerability Management
- Escalate Critical / Major incidents to L3 / Security Lead with a complete evidence package and incident timeline
Infrastructure Support (NOC)
- Investigate and resolve VM performance, Azure Files / Storage, and Azure Backup issues
- Troubleshoot networking issues (VNets, NSGs, UDRs, VPN, ExpressRoute) and PaaS service failures (App Services, Functions, Key Vault access)
- Implement approved configuration changes (ARM/Bicep, NSG rules, RBAC adjustments) within change-management process
- Validate SQL backup/restore operations and triage SQL performance issues
- Resolve Conditional Access / federation / SSO incidents in Entra ID
Client & Internal Coordination
- Serve as the technical escalation point for L1 analysts during shift handovers
- Communicate incident status, recommended actions, and timelines to clients using approved templates
- Coordinate with developers and L3 engineers on bug reproduction and complex root-cause analysis
- Participate in shift handovers, ensuring all open incidents have complete context
Documentation & Continuous Improvement
- Maintain a complete incident record in the ticketing system (timeline, evidence, actions, outcomes)
- Contribute to runbooks, playbooks, and the internal knowledge base
- Recommend SIEM rule tuning and detection improvements based on observed false positives and missed detections (implementation owned by L3)
- Support onboarding of new clients (Defender / Sentinel connector deployment, baseline configuration validation)
Requirements
Must have
- 2+ years of hands-on experience in a SOC, NOC, or IT support role with a security focus
- Working knowledge of Microsoft Defender XDR or Microsoft Sentinel (production experience, not just training)
- Basic KQL - able to write and modify queries for investigation and scoping
- Practical experience with Entra ID / Azure AD administration (users, groups, MFA, Conditional Access basics)
- Experience handling incidents end-to-end: triage → investigation → containment → documentation
- English B2+ (written and spoken); Ukrainian native or fluent
- Willingness to work in a 24x7 rotating shift model
Strong plus
- Microsoft Security Operations Analyst certification (SC-200)
- Hands-on experience with both Defender XDR and Sentinel
- Azure networking troubleshooting (VNets, NSGs, VPN, ExpressRoute)
- Experience with SOAR / Logic Apps / playbook authoring
- Prior MSSP or multi-tenant environment experience
Nice to have
- Microsoft Security, Compliance, and Identity Fundamentals (SC-900)
- Microsoft Azure Administrator Associate (AZ-104)
- Microsoft Azure Fundamentals (AZ-900)
- Microsoft 365 Fundamentals (MS-900)
- ITIL 4 Foundation
- Scripting experience (PowerShell, KQL advanced, Python basics)
We Offer
- Opportunity to work in a dynamic and innovative environment
- Competitive salary
- Remote work options
- Professional development opportunities
About the Company
REW Technology is a leading provider of managed NOC/SOC services, dedicated to delivering top-notch security solutions to our clients. Join our team and be part of a company that values expertise, innovation, and continuous improvement.