06 sep
|
Tata Consultancy Services
|
Guadalajara
06 sep
Tata Consultancy Services
Guadalajara
TCS is looking for a SOC Microsoft Sentinel AnalystWork modality: Hybrid(Candidate needs to be located or relocate to Querétaro, CDMX, Guadalajara or Monterrey, it will be requested to attend office at least 3 day per week)Role PurposeThe SOC Microsoft Sentinel Analyst monitors, detects, investigates, and responds to cybersecurity events using Microsoft Sentinel and the Microsoft security ecosystem.
The role supports Customer's integral i SOC by delivering rapid threat detection, disciplined incident response, reliable case management, and continuous optimization of Sentinel monitoring capabilities.Experience and Behavioral Competencies- Advance English communication
- 2-4 years of experience in SOC, SIEM, or cybersecurity operations, with experience calibrated to role seniority.
- Practical Microsoft Sentinel experience in an enterprise-scale monitoring environment is strongly preferred.
- Strong investigative thinking, disciplined documentation, customer focus, ownership, and attention to detail.
- Clear written and verbal communication, collaboration across global teams, and composure during high-severity incidents.
- Ability and willingness to work within an approved 24x7 rotational shift model.Fundamental and Required Technical Skills- Hands-on Microsoft Sentinel operations, alert triage, incident investigation, and case management.
- Working proficiency in Kusto Query Language for investigation and threat hunting.
- Understanding of Microsoft Defender XDR and its endpoint, identity, cloud, and Microsoft 365 security signals.
- Working knowledge of MITRE ATT&CK; and a structured Incident Response lifecycle; familiarity with NIST ****** is preferred.
- Foundational knowledge of TCP/IP, DNS, email security, firewalls, proxies, VPNs, and common network attack patterns.
- Working knowledge of Windows, Active Directory, Microsoft Entra ID, authentication events, endpoint telemetry, and privilege-related threats.
- Experience creating and maintaining high-quality incident records in Service Now or a comparable ITSM platform.
- Security monitoring knowledge across Azure and Microsoft 365 environments.Core Operational Responsibilities- Monitor, prioritize, and investigate alerts and incidents within Microsoft Sentinel.
- Analyze suspicious activity across cloud, endpoint, identity, email, application, and network data sources.
- Perform alert triage, validate the security event, determine scope and severity, and document the investigation rationale.
- Correlate events across Microsoft Sentinel, Microsoft Defender XDR, identity systems, cloud services, and integrated security tools.
- Escalate incidents to L2/L3, Major Incident Management, or other resolver groups according to playbooks and escalation matrices.
- Execute approved response actions and automated playbooks where authorized.
- Maintain accurate incident records, work notes, evidence, ownership, timestamps, and handover details in Service Now.
- Provide clear shift handovers and maintain follow-the-sun operational continuity.What we offer to you:- Direct contract (indeterminate time with initial probation period)
- Full payroll scheme
- Benefits of the law and above
📌 Soc Microsoft Sentinel Analyst (Guadalajara)
🏢 Tata Consultancy Services
📍 Guadalajara