L2 Support Specialist / NOC-SOC Incident Handler
REW Technology · Ukraine
Skills in this posting
Extracted from the posting text by the instrument — the demand side, read literally.
The posting
Professional Summary Experienced L2 Support Specialist / Incident Handler with 2–4 years of hands-on experience in 24x7 NOC/SOC operations and Microsoft cloud environments.
Skilled in in-depth investigation and containment of security incidents using the Microsoft Defender XDR suite (Defender for Endpoint, Office 365, Identity, Cloud Apps) and Microsoft Sentinel, as well as in Azure and Entra ID infrastructure troubleshooting.
Acts as the escalation point for L1 analysts, coordinates containment with IT Operations, and drives incidents from validated alert through eradication and recovery within agreed SLAs. Strong written and verbal communication in Ukrainian and English, with a structured, evidence-based approach to incident documentation.
Project(s) L2 Support Engineer will join an existing 24x7 support team that delivers managed NOC/SOC services to multiple clients, acting as the second-line escalation tier for both infrastructure and security incidents. Key Skills & Competencies
In-depth incident investigation across Microsoft Defender XDR and Microsoft Sentinel
KQL query authoring for log review, correlation, and scoping of compromise
Containment actions: device isolation, account disable, session revocation, MFA re-registration, token revocation, email Search & Purge
Azure infrastructure troubleshooting: VMs, Azure Files/Storage, Azure Backup, App Services, Functions, Key Vault
Networking: VNets, subnets, NSGs, UDRs, VPN gateways, ExpressRoute (troubleshooting level)
Entra ID: Conditional Access, federation/SSO troubleshooting, RBAC adjustments
Implementation of approved infrastructure changes (ARM/Bicep updates, configuration changes)
SQL PaaS/IaaS troubleshooting (query performance triage, backup/restore validation)
Coordination of containment activities with IT Operations and client stakeholders
Reviewing and approving pending actions in the Defender Action Center (AIR semi-auto workflows)
Building and refining incident timelines and evidence packages for L3 / post-incident review
Mentoring L1 analysts; reviewing tickets for accuracy and completeness
Bilingual: Ukrainian (native) and English (B2+ / C1)
Responsibilities Handled Incident Investigation & Response (SOC)
Take ownership of incidents escalated by L1 within agreed SLA timeframes
Conduct in-depth investigation in Microsoft Defender XDR and Microsoft Sentinel: deep KQL queries, log review, cross-product correlation across Defender for Endpoint / Office 365 / Identity / Cloud Apps
Identify probable cause, determine scope of compromise (blast radius), and document affected users, devices, and identities
Execute containment actions using Defender tooling
Endpoint: isolate device, stop processes, collect investigation packages
User account: force password reset, revoke sessions in Entra ID, force MFA re-registration, disable/block accounts as needed
Email: Search & Purge / Purview eDiscovery to remove malicious messages
Cloud apps: block app or revoke OAuth tokens via Defender for Cloud Apps
Review pending actions in the Defender Action Center; approve, modify, or reject AIR-recommended remediations
Coordinate eradication and recovery activities with IT Operations (patching, account restoration, system rebuilds)
Monitor for recurrence during the post-incident observation window and confirm eradication via MDE Threat & Vulnerability Management
Escalate Critical / Major incidents to L3 / Security Lead with a complete evidence package and incident timeline
Infrastructure Support (NOC)
Investigate and resolve VM performance, Azure Files / Storage, and Azure Backup issues
Troubleshoot networking issues (VNets, NSGs, UDRs, VPN, ExpressRoute) and PaaS service failures (App Services, Functions, Key Vault access)
Implement approved configuration changes (ARM/Bicep, NSG rules, RBAC adjustments) within change-management process
Validate SQL backup/restore operations and triage SQL performance issues
Resolve Conditional Access / federation / SSO incidents in Entra ID
Client & Internal Coordination
Serve as the technical escalation point for L1 analysts during shift handovers
Communicate incident status, recommended actions, and timelines to clients using approved templates
Coordinate with developers and L3 engineers on bug reproduction and complex root-cause analysis
Participate in shift handovers, ensuring all open incidents have complete context
Documentation & Continuous Improvement
Maintain a complete incident record in the ticketing system (timeline, evidence, actions, outcomes)
Contribute to runbooks, playbooks, and the internal knowledge base
Recommend SIEM rule tuning and detection improvements based on observed false positives and missed detections (implementation owned by L3)
Support onboarding of new clients (Defender / Sentinel connector deployment, baseline configuration validation)
Requirements Must have
2+ years of hands-on experience in a SOC, NOC, or IT support role with a security focus
Working knowledge of Microsoft Defender XDR or Microsoft Sentinel (production experience, not just training)
Basic KQL — able to write and modify queries for investigation and scoping
Practical experience with Entra ID / Azure AD administration (users, groups, MFA, Conditional Access basics)
Experience handling incidents end-to-end: triage → investigation → containment → documentation
English B2+ (written and spoken); Ukrainian native or fluent
Willingness to work in a 24x7 rotating shift model
Strong plus
Microsoft Security Operations Analyst certification (SC-200)
Hands-on experience with both Defender XDR and Sentinel
Azure networking troubleshooting (VNets, NSGs, VPN, ExpressRoute)
Experience with SOAR / Logic Apps / playbook authoring
Prior MSSP or multi-tenant environment experience
Nice to have
Microsoft Security, Compliance, and Identity Fundamentals (SC-900)
Microsoft Azure Administrator Associate (AZ-104)
Microsoft Azure Fundamentals (AZ-900)
Microsoft 365 Fundamentals (MS-900)
ITIL 4 Foundation
Scripting experience (PowerShell, KQL advanced, Python basics)
Availability
Shift pattern to be confirmed; rotation includes nights and weekends
On-call rotation may be required as part of L2 escalation coverage
Originally posted on Himalayas
Excerpt from the original listing. The full, current text lives at the source. Read and apply there →
The PivotHop read
- What a customer support specialist actually earnsmedian, seniority, by country
- Alternative careers for a customer support specialistevery measured route out
- All open customer support specialist rolesthe full board
Where these skills also reach
Adjacent occupations measured from the same postings — readiness is what a customer support specialist’s profile already covers.
- 294 open customer success manager roles37% readiness from customer support specialist
- 475 open it support specialist roles35% readiness from customer support specialist
- 395 open executive assistant roles30% readiness from customer support specialist
- 600 open sales representative roles26% readiness from customer support specialist
More customer support specialist roles
- Manager, Customer Support EngineeringFivetran · APAC, Australia
- Trader Support Specialist (UK)Tradeify · United Kingdom
- Customer Service RepresentativePainPoint Health · United States
- (German & English, weekend shifts) Customer Support ConsultantSupportYourApp · Serbia
- Customer Support Specialist – Immobilienverwaltung - Remote Deutschland (m/f/d)Impower · Germany
Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.