R

L2 Support Specialist / NOC-SOC Incident Handler

REW Technology · Ukraine

RemoteWorkplace
TodayPosted · Aug 6
HimalayasSource
Apply now Opens the original posting at REW Technology. PivotHop does not host applications.

Skills in this posting

Extracted from the posting text by the instrument — the demand side, read literally.

The posting

Professional Summary Experienced L2 Support Specialist / Incident Handler with 2–4 years of hands-on experience in 24x7 NOC/SOC operations and Microsoft cloud environments.

Skilled in in-depth investigation and containment of security incidents using the Microsoft Defender XDR suite (Defender for Endpoint, Office 365, Identity, Cloud Apps) and Microsoft Sentinel, as well as in Azure and Entra ID infrastructure troubleshooting.

Acts as the escalation point for L1 analysts, coordinates containment with IT Operations, and drives incidents from validated alert through eradication and recovery within agreed SLAs. Strong written and verbal communication in Ukrainian and English, with a structured, evidence-based approach to incident documentation.

Project(s) L2 Support Engineer will join an existing 24x7 support team that delivers managed NOC/SOC services to multiple clients, acting as the second-line escalation tier for both infrastructure and security incidents. Key Skills & Competencies

In-depth incident investigation across Microsoft Defender XDR and Microsoft Sentinel

KQL query authoring for log review, correlation, and scoping of compromise

Containment actions: device isolation, account disable, session revocation, MFA re-registration, token revocation, email Search & Purge

Azure infrastructure troubleshooting: VMs, Azure Files/Storage, Azure Backup, App Services, Functions, Key Vault

Networking: VNets, subnets, NSGs, UDRs, VPN gateways, ExpressRoute (troubleshooting level)

Entra ID: Conditional Access, federation/SSO troubleshooting, RBAC adjustments

Implementation of approved infrastructure changes (ARM/Bicep updates, configuration changes)

SQL PaaS/IaaS troubleshooting (query performance triage, backup/restore validation)

Coordination of containment activities with IT Operations and client stakeholders

Reviewing and approving pending actions in the Defender Action Center (AIR semi-auto workflows)

Building and refining incident timelines and evidence packages for L3 / post-incident review

Mentoring L1 analysts; reviewing tickets for accuracy and completeness

Bilingual: Ukrainian (native) and English (B2+ / C1)

Responsibilities Handled Incident Investigation & Response (SOC)

Take ownership of incidents escalated by L1 within agreed SLA timeframes

Conduct in-depth investigation in Microsoft Defender XDR and Microsoft Sentinel: deep KQL queries, log review, cross-product correlation across Defender for Endpoint / Office 365 / Identity / Cloud Apps

Identify probable cause, determine scope of compromise (blast radius), and document affected users, devices, and identities

Execute containment actions using Defender tooling

Endpoint: isolate device, stop processes, collect investigation packages

User account: force password reset, revoke sessions in Entra ID, force MFA re-registration, disable/block accounts as needed

Email: Search & Purge / Purview eDiscovery to remove malicious messages

Cloud apps: block app or revoke OAuth tokens via Defender for Cloud Apps

Review pending actions in the Defender Action Center; approve, modify, or reject AIR-recommended remediations

Coordinate eradication and recovery activities with IT Operations (patching, account restoration, system rebuilds)

Monitor for recurrence during the post-incident observation window and confirm eradication via MDE Threat & Vulnerability Management

Escalate Critical / Major incidents to L3 / Security Lead with a complete evidence package and incident timeline

Infrastructure Support (NOC)

Investigate and resolve VM performance, Azure Files / Storage, and Azure Backup issues

Troubleshoot networking issues (VNets, NSGs, UDRs, VPN, ExpressRoute) and PaaS service failures (App Services, Functions, Key Vault access)

Implement approved configuration changes (ARM/Bicep, NSG rules, RBAC adjustments) within change-management process

Validate SQL backup/restore operations and triage SQL performance issues

Resolve Conditional Access / federation / SSO incidents in Entra ID

Client & Internal Coordination

Serve as the technical escalation point for L1 analysts during shift handovers

Communicate incident status, recommended actions, and timelines to clients using approved templates

Coordinate with developers and L3 engineers on bug reproduction and complex root-cause analysis

Participate in shift handovers, ensuring all open incidents have complete context

Documentation & Continuous Improvement

Maintain a complete incident record in the ticketing system (timeline, evidence, actions, outcomes)

Contribute to runbooks, playbooks, and the internal knowledge base

Recommend SIEM rule tuning and detection improvements based on observed false positives and missed detections (implementation owned by L3)

Support onboarding of new clients (Defender / Sentinel connector deployment, baseline configuration validation)

Requirements Must have

2+ years of hands-on experience in a SOC, NOC, or IT support role with a security focus

Working knowledge of Microsoft Defender XDR or Microsoft Sentinel (production experience, not just training)

Basic KQL — able to write and modify queries for investigation and scoping

Practical experience with Entra ID / Azure AD administration (users, groups, MFA, Conditional Access basics)

Experience handling incidents end-to-end: triage → investigation → containment → documentation

English B2+ (written and spoken); Ukrainian native or fluent

Willingness to work in a 24x7 rotating shift model

Strong plus

Microsoft Security Operations Analyst certification (SC-200)

Hands-on experience with both Defender XDR and Sentinel

Azure networking troubleshooting (VNets, NSGs, VPN, ExpressRoute)

Experience with SOAR / Logic Apps / playbook authoring

Prior MSSP or multi-tenant environment experience

Nice to have

Microsoft Security, Compliance, and Identity Fundamentals (SC-900)

Microsoft Azure Administrator Associate (AZ-104)

Microsoft Azure Fundamentals (AZ-900)

Microsoft 365 Fundamentals (MS-900)

ITIL 4 Foundation

Scripting experience (PowerShell, KQL advanced, Python basics)

Availability

Shift pattern to be confirmed; rotation includes nights and weekends

On-call rotation may be required as part of L2 escalation coverage

Originally posted on Himalayas

Excerpt from the original listing. The full, current text lives at the source. Read and apply there →

The PivotHop read

Where these skills also reach

Adjacent occupations measured from the same postings — readiness is what a customer support specialist’s profile already covers.

More customer support specialist roles

Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.

© 2026 PivotHopReal data, real career moves