Intras Cloud Services is seeking a skilled and proactive GSOC Analyst Level 2 to serve as a senior escalation resource within our Global Security Operations Center. In this role, you will investigate complex security incidents, perform threat hunting, and drive response efforts across our Microsoft 365 and Azure cloud environments. You will mentor and support Level 1 analysts, ensuring timely and accurate escalation handling while continuously improving our security posture. This is a hands-on technical role for a cybersecurity professional with a strong cloud security foundation and experience leveraging AI-assisted tools to detect, analyze, and mitigate modern threats.
Key Responsibilities
- Act as the primary escalation point for GSOC Level 1 analysts, triaging complex or high-severity alerts and guiding analysts through investigation workflows.
- Lead end-to-end incident response activities, including detection, containment, eradication, recovery, and post-incident review documentation.
- Conduct proactive threat hunting across Microsoft Sentinel, Defender XDR, and connected log sources to identify indicators of compromise (IOCs) and attacker TTPs.
- Develop, tune, and maintain SIEM detection rules, analytic queries (KQL), and alert logic to reduce false positives and improve signal fidelity.
- Monitor and investigate security events across Microsoft 365 environments, including Defender for Office 365, Purview, and the Microsoft Compliance Center.
- Administer and analyze alerts from Azure Security Center (Microsoft Defender for Cloud), Azure AD / Entra ID, and related Azure services.
- Leverage AI-assisted security tools — including Microsoft Copilot for Security — to accelerate threat analysis, investigation summaries, and recommended remediation steps.
- Perform vulnerability assessments and coordinate remediation efforts with IT and infrastructure teams, tracking findings to resolution.
- Author detailed incident reports, runbooks, and standard operating procedures (SOPs) to improve team documentation and knowledge transfer.
- Collaborate cross-functionally with IT, cloud engineering, and compliance teams to implement security controls and enforce policy.
- Support the continuous improvement of GSOC processes, playbooks, and automation workflows to increase team efficiency and response speed.
- Stay current on emerging threat intelligence, CVEs, attack campaigns, and adversary techniques relevant to cloud and Microsoft environments.