Hiring.Camp

Lead SOC Analyst

KALSOFT

·

Today

Location
Doha, Qatar
Workplace
Onsite
Type
Full-time
Seniority
Lead
Experience
5+ years
Education
Bachelor
Closing date
Today
Source
ApplyToJob

Description

Location: Onsite – Doha, Qatar
Experience: 5+ Years
Employment Type: Full-Time

About the Role

KalSoft is looking for a Lead SOC Analyst to lead security monitoring, threat detection, investigation, and incident response for AI agents and agentic platforms across the Microsoft ecosystem. The role focuses on securing Microsoft 365, Microsoft Purview, Microsoft Defender, Microsoft Entra ID, Microsoft Sentinel, and Azure AI Foundry. The candidate will oversee AI security monitoring, incident response, compliance, and containment activities while collaborating with security, identity, governance, and business teams in a 24/7 SOC environment.

Key Responsibilities

  • Monitor AI agents and agentic platforms across Microsoft 365 Agents, Microsoft Purview, Microsoft Defender XDR, Microsoft Entra ID, Microsoft Sentinel, and Azure AI Foundry.
  • Detect, investigate, and respond to AI-related security threats, including:
    • Agent takeover and account compromise.
    • Privilege drift and excessive permissions.
    • Prompt injection attacks and data poisoning.
    • Shadow or unauthorized AI agents.
    • Suspicious agent behaviour and anomalous activity.
  • Conduct security incident triage, investigation, and escalation in accordance with SOC procedures.
  • Execute approved containment and remediation actions, including access token revocation, Conditional Access enforcement, agent suspension or quarantine, and privileged access restrictions.
  • Develop, maintain, and fine-tune detection use cases, analytics rules, and monitoring content in Microsoft Sentinel and Defender XDR.
  • Manage agent risk classifications, security certifications, evidence repositories, audit records, and compliance documentation.
  • Conduct recurring assurance reviews, security validations, and control testing to ensure agents comply with governance requirements.
  • Track and report detection, response, and containment SLAs, KPIs, and KRIs.
  • Collaborate with client security teams, identity administrators, governance and compliance teams, Microsoft support, and AI agent owners to coordinate threat response and risk mitigation.
  • Support threat hunting and continuous improvement of AI security monitoring capabilities.
  • Develop and maintain playbooks, incident response procedures, and operational runbooks for AI-related security events.
  • Participate in a 24/7 operational rota and on-call support for continuous security monitoring and incident response.

Requirements

  • Bachelor's degree in a relevant discipline.
  • 5+ years of experience in SOC, Security Operations, Managed Security Services (MSSP), Cyber Defence, or Incident Response environments.
  • Hands-on experience with:
    • Microsoft Sentinel and Microsoft Defender XDR.
    • Microsoft Purview and Microsoft Entra ID.
    • Conditional Access and Continuous Access Evaluation (CAE).
    • Privileged Identity Management (PIM).
  • Experience investigating identity-based attacks, authorization issues, insider threats, and cloud security incidents.
  • Practical experience creating, tuning, and maintaining detection rules, alerts, and investigation workflows.
  • Experience supporting security monitoring in cloud-native and Microsoft security environments.
  • Experience working in a 24/7 security operations environment.
  • Strong proficiency in Kusto Query Language (KQL) for threat hunting, monitoring, and investigation.
  • Strong understanding of Role-Based Access Control (RBAC), Privileged Access Management (PAM), least privilege principles, and identity and access governance.
  • Knowledge of AI security technologies and platforms, including:
    • Microsoft Copilot Studio.
    • Microsoft 365 Agents (Agent 365).
    • Azure AI Foundry.
    • Agent governance and lifecycle management.
  • Familiarity with AI and agentic security frameworks and standards, including:
    • OWASP Top 10 for LLM Applications and Agentic Security.
    • MITRE ATLAS.
    • NIST AI Risk Management Framework (AI RMF).
  • Strong understanding of cloud security, threat detection methodologies, and incident response best practices.
  • Excellent analytical, problem-solving, and decision-making skills, particularly during active security incidents.
  • Strong documentation, evidence collection, audit support, and reporting skills.
  • Excellent verbal and written communication skills, with the ability to engage technical and non-technical stakeholders.
  • Ability to manage priorities and respond effectively in high-pressure operational environments.
  • Commitment to continuous learning in AI security and cyber defence.
  • Willingness to participate in a 24/7 operational support model and on-call rota.

Skills

AzureSOCRisk ManagementCompliance

Similar Jobs

8

Lead SOC Analyst

Swift·OPC US, US

2mo ago

Lead SOC Analyst

Ufpi·Grand Rapids, MI·Onsite

2mo ago

Lead SOC Analyst/Shift Lead

Certes·Milton Keynes, Buckinghamshire

2d ago

Lead, Security(T1 SOC Analyst)

Professional Kyndryl·Budapest BUDAONE, Hungary·Remote

1w ago

SOC Analyst (Shift Lead) (f/m/d)

Danaher·POL – Krakow – Cytiva, Poland·Remote, Hybrid, Onsite

3w ago

SOC Analyst (Shift Lead) (f/m/d)

Danaher·POL – Krakow – Cytiva, Poland·Remote, Hybrid, Onsite

3w ago

Senior SOC Analyst/SOC Lead

Nttlimited·Hyderabad, India·Hybrid

4mo ago

Senior Analyst / Lead, Cyber Defence (SOC)

Circles is·ID Jakarta, Indonesia·Hybrid

10mo ago