K

Lead SOC Analyst

KALSOFT

Doha, Doha Municipality, Qatar · Full Time

Be the first to apply

Experience
5+ yrs
Salary
—
Openings
1
Posted
5 days ago
Work mode
In office
Education
Bachelor's degree
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About the Role

KalSoft seeks an experienced Lead SOC Analyst to spearhead security monitoring, threat detection, investigation, and incident response that focuses specifically on AI agents and agentic platforms within the Microsoft ecosystem. The position involves protecting Microsoft 365, Purview, Defender, Entra ID, Sentinel, and Azure AI Foundry environments.

Key Responsibilities

  • Observe and monitor AI agents and automated platforms across Microsoft security services including Microsoft 365, Purview, Defender XDR, Entra ID, Sentinel, and Azure AI Foundry.
  • Identify, analyze, and respond to security threats related to AI, such as agent hijacking, account compromise, escalation of privileges, prompt injections, data contamination, rogue AI agents, and suspicious behaviors.
  • Perform triage, investigation, and escalation of security incidents following SOC protocols.
  • Implement containment and remediation actions approved by procedures, such as revoking access tokens, enforcing Conditional Access policies, suspending or quarantining agents, and limiting privileged access.
  • Create, update, and refine detection use cases, monitoring rules, and analytics content within Microsoft Sentinel and Defender XDR.
  • Manage classification of agent risks, oversee security certifications, maintain evidence and audit records, and keep compliance documentation current.
  • Conduct regular assurance reviews, perform security validations, and test controls to verify agents meet governance standards.
  • Monitor and report on SLAs, KPIs, and KRIs related to detection, response, and containment efforts.
  • Collaborate with client security, identity administrators, governance teams, Microsoft support, and AI agent stakeholders to coordinate threat mitigation and responses.
  • Assist threat hunting activities and support continuous enhancement of AI security monitoring capabilities.
  • Develop and maintain operational playbooks, incident response protocols, and runbooks pertaining to AI security incidents.
  • Participate in a 24/7 SOC operational rota providing ongoing monitoring and incident response coverage.

Qualifications and Requirements

  • Bachelor's degree in a relevant field.
  • Minimum of 5 years experience working in SOC, Security Operations, MSSP, Cyber Defence, or Incident Response.
  • Proven practical experience with Microsoft Sentinel, Defender XDR, Purview, Entra ID, Conditional Access, Continuous Access Evaluation (CAE), and Privileged Identity Management (PIM).
  • Experience investigating identity-centric attacks, insider threats, authorization problems, and cloud security events.
  • Hands-on ability to create, tune, and sustain detection alerts, workflows, and rules.
  • Familiar working in cloud-native Microsoft security environments and a 24/7 operational Security Operations Center setting.
  • Strong command of Kusto Query Language (KQL) for crafting threat hunting queries, monitoring, and investigations.
  • Deep understanding of RBAC, PAM, least privilege, and identity governance best practices.
  • Knowledgeable about AI security platforms including Microsoft Copilot Studio, Microsoft 365 Agents (Agent 365), Azure AI Foundry, and AI agent lifecycle management.
  • Aware of AI and agentic security standards such as OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI Risk Management Framework (AI RMF).
  • Thorough understanding of cloud security, threat detection methodologies, and incident response strategies.
  • Excellent analytical and decision-making skills, especially in handling active security incidents.
  • Strong skills in documentation, evidence gathering, audit facilitation, and detailed reporting.
  • Effective communication skills for engaging both technical and non-technical audiences.
  • Aptitude for managing priorities and performing well under pressure in operational environments.
  • Dedication to continuous professional growth in AI security and cyber defence.
  • Willingness to join a 24/7 SOC shift roster and provide on-call incident response.

Minimum education

Bachelor's Degree

How they work

Communication Problem Solving Decision Making Stress Management

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer