Haystack
← Back to Jobs
Technology
AT

SOC Analyst

Ace Technologies, Inc.United States🇺🇸United StatesPosted Sep 21, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
United States
Posted
Yesterday
SplunkAzure

Job Description

Required Qualifications

  • SOC analyst experience, including at least 1 year in an escalation/L2 capacity...
  • Hands-on production experience with SentinelOne Singularity (Console, Deep Visibility, Storyline, RemoteOps).
  • Solid understanding of Windows/Linux/macOS internals, common attack techniques, and the MITRE ATT&CK framework.
  • Experience with case management/ticketing platforms and SIEM log review.
  • Strong written communication skills for incident documentation and playbook authoring.

Preferred Qualifications

  • SentinelOne certification(s) (e.g., SentinelOne Certified Analyst/Engineer).
  • Experience with SOAR platforms (e.g., Palo Alto XSOAR, Swimlane, Tines) for playbook automation.
  • Exposure to identity-centric investigation tools or entity/behavioral intelligence platforms.
  • Industry certifications: GCIH, GCIA, Security+, CySA+, or equivalent.
  • Prior MSSP/MDR environment experience supporting multiple client tenants.

Position Summary
Our security architecture deeply relies on Microsoft Sentinel and Microsoft Defender XDR as our cloud-native SIEM and SentinelOne as well as Microsoft Defender for Endpoint as our enterprise Endpoint Detection and Response (EDR) platform. The ideal candidate possesses a strong command of Kusto Query Language (KQL), extensive experience pivoting between endpoint forensics and cloud infrastructure logs, and a proven track record of neutralizing threats, and have deep understanding of Microsoft Azure PaaS and SaaS security technologies.

  • MUST HAVE experience here in Splunk and Splunk ES.
  • An experienced and analytical Level 2 (L2) Security Operations Center (SOC) Analyst to join customer team. In this role, act as the primary escalation point for complex security anomalies. Responsible for conducting deep-dive incident investigations, correlating cross-domain telemetry, and driving containment strategies.
  • The ideal candidate possesses a strong command of Kusto Query Language (KQL), extensive experience pivoting between endpoint forensics and cloud infrastructure logs, and a proven track record of neutralizing threats, and have deep understanding of Microsoft Azure PaaS and SaaS security technologies.
  • Advanced Incident Investigation: Analyze and validate high-priority alerts escalated by L1 analysts. Utilize Microsoft Sentinel and Defender XDR to correlate cross-platform data sources (Azure AD, Microsoft 365, network firewalls, On-prem AD, SaaS services and multi-cloud logs) to determine the true scope and impact of an incident
  • Execute containment playbooks to neutralize threats. This includes isolating compromised endpoints directly through SentinelOne  and Microsoft Defender for Endpoint, revoking compromised cloud sessions via Azure AD, and blocking malicious Indicators of Compromise (IOCs) across security perimeters.  
  • Detection Engineering & Tuning: Author, refine, and optimize Microsoft Sentinel Analytics Rules and threat hunting queries using Kusto Query Language (KQL) to minimize false positives and capture emerging threat techniques.
  • SOAR Automation: Build and modify automated response logic apps and playbooks within MS Sentinel to improve the SOC's Mean Time to Respond (MTTR Collaboration & Mentorship: Provide technical guidance, escalation support, and constructive feedback to Level 1 Analysts to uplift overall team competency.

Similar jobs