Deskripsi pekerjaan Security Operations Analyst - SOC - (L2) - Banking Project PT Aktualisasi Gratia Talenta Indonesia
Key Responsibilities:
- Provide L2 security operations support for Microsoft Defender for Endpoint, Microsoft Defender for Cloud Apps, and Microsoft Purview.
- Monitor, review, and perform initial triage of security alerts, incidents, requests, and customer tickets.
- Perform initial investigation of MDE alerts, incidents, device timelines, antivirus detections, device health, onboarding status, sensor health, and endpoint policies.
- Review and investigate MDCA alerts, user activities, connected applications, cloud discovery information, activity policies, anomaly detections, and connector status.
- Review Microsoft Purview alerts and events related to Information Protection, sensitivity labels, Data Loss Prevention (DLP), Endpoint DLP, Insider Risk Management, and Data Lifecycle Management.
- Assess alert severity, potential user impact, available evidence, and required next steps based on approved procedures.
- Collect and document relevant logs, screenshots, diagnostic packages, alert details, audit records, policy status, connector status, and investigation evidence.
- Perform basic troubleshooting using approved runbooks, knowledge articles, SOPs, and support procedures.
- Manage and update customer tickets through ServiceNow (SNOW), ensuring accurate categorisation, prioritisation, investigation notes, evidence, customer updates, and closure information.
- Escalate unresolved, high-impact, or complex security issues to L2/L3, platform SMEs, Microsoft Support, or relevant client technical teams.
- Coordinate with Endpoint, Intune, Identity, Compliance, Infrastructure, and Operations teams when required.
- Maintain accurate documentation and ensure all incidents and requests are handled within agreed SLA and operational procedures.
- Support continuous improvement by identifying recurring issues and providing feedback on runbooks and knowledge articles.
Requirements:
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or a related field is preferred.
- Equivalent practical experience in cybersecurity, Microsoft security operations, or IT support may also be considered.
- 3–5 years of experience in SOC, cybersecurity operations, security support, service desk, endpoint support, or Microsoft 365 operational support.
- Working knowledge of Microsoft Defender for Endpoint (MDE) and the Microsoft Defender portal.
- Working knowledge of Microsoft Defender for Cloud Apps (MDCA) and cloud security monitoring.
- Ability to perform basic investigation and triage of security alerts and incidents.
- Understanding of endpoint health, device onboarding, antivirus detections, device timelines, and security policy status.
- Familiarity with cloud application activities, connected applications, cloud discovery, anomaly detection, and security policies.
Preferred Certifications:
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Microsoft Certified: Endpoint Administrator Associate (MD-102)
- Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)
- Microsoft Certified: Information Security Administrator Associate (SC-401)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)


