About the role
Hi, Hope you are doing great. This is Abhishek from ValueMomentum Inc.
Job Description: Onsite SOC Analyst
Location: Ontario (Onsite)
Role Overview
The Onsite SOC Analyst is responsible for supporting 24x7 Security Operations Center (SOC) activities, including monitoring, detection, investigation, and response to cybersecurity threats. The role involves working closely with the onsite SOC Team Lead / Manager and adhering to defined SOPs, runbooks, and incident response processes. The analyst will leverage Microsoft Sentinel as the SIEM platform and Microsoft Defender (Azure Defender) suite for security operations across endpoints, network devices, applications, and cloud environments.
Key Responsibilities
Security Monitoring & Alert Handling Monitor security alerts and events in Microsoft Sentinel and Microsoft Defender platforms. Perform initial triage, analysis, and prioritization of alerts. Correlate events across multiple sources including endpoints, network devices, applications, servers, and cloud services. Identify false positives, escalate genuine threats, and ensure proper documentation of findings. Maintain continuous monitoring discipline across assigned shifts.
Incident Response & Ticket Management
Acknowledge, investigate, and respond to security incidents within defined SLAs. Follow incident response procedures, SOPs, and runbooks for handling security events. Create, update, and manage tickets in ITSM tools (e.g., ServiceNow). Escalate incidents to SOC Lead or relevant teams based on severity and impact. Ensure timely resolution or handover of incidents across shifts.
Microsoft Security Operations
Work with Microsoft Defender suite including Defender for Endpoint, Defender for Office 365, Defender for Cloud. Investigate alerts generated from Azure Defender / Microsoft Defender tools. Support threat detection, enrichment, and basic threat hunting activities. Assist in correlating alerts between Microsoft Sentinel and Defender platforms.
Process Adherence & Documentation
Follow defined SOPs, playbooks, and escalation matrices strictly. Update SOPs and runbooks based on operational learnings and new threats. Maintain accurate and complete documentation of incidents, actions taken, and outcomes. Ensure proper shift handover documentation and communication.
Automation & Continuous Improvement
Support implementation of automation using Microsoft Sentinel playbooks, Logic Apps, and PowerShell. Identify repetitive tasks and suggest automation opportunities. Assist in tuning detection rules and reducing false positives. Contribute to continuous improvement of SOC operations and processes.
Collaboration & Reporting
Collaborate with infrastructure, application, and security teams for incident resolution. Communicate effectively with SOC Lead and stakeholders during incidents. Publish shift-wise status reports, including incidents handled, escalations, and observations. Participate in incident reviews and knowledge-sharing sessions.
Service Delivery & Compliance
Ensure adherence to SLAs, KPIs, and KRAs defined for SOC operations. Maintain quality of incident handling, documentation, and reporting. Support audit, compliance, and governance requirements. Follow organizational security policies and standards.
Required Skills & Qualifications
Technical Skills Hands-on experience or working knowledge of Microsoft Sentinel (SIEM). Familiarity with Microsoft Defender / Azure Defender technologies. Basic understanding of security operations, incident response, and threat analysis. Knowledge of networking concepts (TCP/IP, DNS, VPN, firewalls). Understanding of Windows/Linux systems and cloud environments. Familiarity with KQL (Kusto Query Language) and basic scripting (PowerShell) is a plus. Awareness of security frameworks such as NIST, ISO 27001, and MITRE ATT&CK.
Soft Skills
Strong analytical and problem-solving abilities. Good communication and reporting skills. Ability to work in a shift-based, high-pressure SOC environment. Strong attention to detail and adherence to processes. Team collaboration and willingness to learn.
Education & Experience
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field. 2–5 years of experience in SOC operations, security monitoring, or incident response roles. Relevant certifications preferred: SC-200, Security+, CEH, AZ-500 (basic level acceptable).
Work Conditions
Full-time onsite role supporting 24x7 SOC operations (rotational shifts). May require night shifts, weekend shifts, and holiday coverage. High-pressure environment requiring quick decision-making and responsiveness. Continuous learning expected to stay updated with evolving threats and technologies.
About ValueMomentum
ValueMomentum is a leading solutions provider for the global property and casualty insurance industry, supported by deep domain and technology capabilities. We help insurers stay ahead with sustained growth and high performance for enhancing stakeholder value and fostering resilient societies. Trusted by over 100 insurers, ValueMomentum is one of the largest services providers exclusively focused on property and casualty. ValueMomentum is headquartered in Piscataway, NJ, with state-of-the-art delivery centers in Piscataway, NJ; Hyderabad, Pune, and Coimbatore in India; Toronto in Canada; and London in the United Kingdom. ValueMomentum is an Equal Opportunity Employer committed to fostering a diverse and inclusive workplace. We make all employment decisions based on qualifications, merit, and business needs, without regard to race, color, religion, sex, gender identity or expression, sexual orientation, national origin, age, disability, protected veteran status, genetic information, or any other characteristic protected by applicable federal, state, or local law. We are also committed to providing reasonable accommodations to qualified individuals with disabilities and applicants throughout the recruitment process, in accordance with applicable laws.
Not the right fit? Search for Security Analyst jobs in Ontario, Canada
About ValueMomentum
ValueMomentum is a leading solutions provider for the global property and casualty insurance industry, supported by deep domain and technology capabilities. We help insurers stay ahead with sustained growth and high performance for enhancing stakeholder value and fostering resilient societies. Trusted by over 100 insurers, ValueMomentum is one of the largest services providers exclusively focused on the property and casualty.
ValueMomentum is headquartered in Piscataway, NJ, with state-of-the-art delivery centers in Piscataway, NJ; Hyderabad, Pune, and Coimbatore in India; Toronto in Canada; and London in the United Kingdom.
Similar Jobs
About the role
Hi, Hope you are doing great. This is Abhishek from ValueMomentum Inc.
Job Description: Onsite SOC Analyst
Location: Ontario (Onsite)
Role Overview
The Onsite SOC Analyst is responsible for supporting 24x7 Security Operations Center (SOC) activities, including monitoring, detection, investigation, and response to cybersecurity threats. The role involves working closely with the onsite SOC Team Lead / Manager and adhering to defined SOPs, runbooks, and incident response processes. The analyst will leverage Microsoft Sentinel as the SIEM platform and Microsoft Defender (Azure Defender) suite for security operations across endpoints, network devices, applications, and cloud environments.
Key Responsibilities
Security Monitoring & Alert Handling Monitor security alerts and events in Microsoft Sentinel and Microsoft Defender platforms. Perform initial triage, analysis, and prioritization of alerts. Correlate events across multiple sources including endpoints, network devices, applications, servers, and cloud services. Identify false positives, escalate genuine threats, and ensure proper documentation of findings. Maintain continuous monitoring discipline across assigned shifts.
Incident Response & Ticket Management
Acknowledge, investigate, and respond to security incidents within defined SLAs. Follow incident response procedures, SOPs, and runbooks for handling security events. Create, update, and manage tickets in ITSM tools (e.g., ServiceNow). Escalate incidents to SOC Lead or relevant teams based on severity and impact. Ensure timely resolution or handover of incidents across shifts.
Microsoft Security Operations
Work with Microsoft Defender suite including Defender for Endpoint, Defender for Office 365, Defender for Cloud. Investigate alerts generated from Azure Defender / Microsoft Defender tools. Support threat detection, enrichment, and basic threat hunting activities. Assist in correlating alerts between Microsoft Sentinel and Defender platforms.
Process Adherence & Documentation
Follow defined SOPs, playbooks, and escalation matrices strictly. Update SOPs and runbooks based on operational learnings and new threats. Maintain accurate and complete documentation of incidents, actions taken, and outcomes. Ensure proper shift handover documentation and communication.
Automation & Continuous Improvement
Support implementation of automation using Microsoft Sentinel playbooks, Logic Apps, and PowerShell. Identify repetitive tasks and suggest automation opportunities. Assist in tuning detection rules and reducing false positives. Contribute to continuous improvement of SOC operations and processes.
Collaboration & Reporting
Collaborate with infrastructure, application, and security teams for incident resolution. Communicate effectively with SOC Lead and stakeholders during incidents. Publish shift-wise status reports, including incidents handled, escalations, and observations. Participate in incident reviews and knowledge-sharing sessions.
Service Delivery & Compliance
Ensure adherence to SLAs, KPIs, and KRAs defined for SOC operations. Maintain quality of incident handling, documentation, and reporting. Support audit, compliance, and governance requirements. Follow organizational security policies and standards.
Required Skills & Qualifications
Technical Skills Hands-on experience or working knowledge of Microsoft Sentinel (SIEM). Familiarity with Microsoft Defender / Azure Defender technologies. Basic understanding of security operations, incident response, and threat analysis. Knowledge of networking concepts (TCP/IP, DNS, VPN, firewalls). Understanding of Windows/Linux systems and cloud environments. Familiarity with KQL (Kusto Query Language) and basic scripting (PowerShell) is a plus. Awareness of security frameworks such as NIST, ISO 27001, and MITRE ATT&CK.
Soft Skills
Strong analytical and problem-solving abilities. Good communication and reporting skills. Ability to work in a shift-based, high-pressure SOC environment. Strong attention to detail and adherence to processes. Team collaboration and willingness to learn.
Education & Experience
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field. 2–5 years of experience in SOC operations, security monitoring, or incident response roles. Relevant certifications preferred: SC-200, Security+, CEH, AZ-500 (basic level acceptable).
Work Conditions
Full-time onsite role supporting 24x7 SOC operations (rotational shifts). May require night shifts, weekend shifts, and holiday coverage. High-pressure environment requiring quick decision-making and responsiveness. Continuous learning expected to stay updated with evolving threats and technologies.
About ValueMomentum
ValueMomentum is a leading solutions provider for the global property and casualty insurance industry, supported by deep domain and technology capabilities. We help insurers stay ahead with sustained growth and high performance for enhancing stakeholder value and fostering resilient societies. Trusted by over 100 insurers, ValueMomentum is one of the largest services providers exclusively focused on property and casualty. ValueMomentum is headquartered in Piscataway, NJ, with state-of-the-art delivery centers in Piscataway, NJ; Hyderabad, Pune, and Coimbatore in India; Toronto in Canada; and London in the United Kingdom. ValueMomentum is an Equal Opportunity Employer committed to fostering a diverse and inclusive workplace. We make all employment decisions based on qualifications, merit, and business needs, without regard to race, color, religion, sex, gender identity or expression, sexual orientation, national origin, age, disability, protected veteran status, genetic information, or any other characteristic protected by applicable federal, state, or local law. We are also committed to providing reasonable accommodations to qualified individuals with disabilities and applicants throughout the recruitment process, in accordance with applicable laws.
Not the right fit? Search for Security Analyst jobs in Ontario, Canada
About ValueMomentum
ValueMomentum is a leading solutions provider for the global property and casualty insurance industry, supported by deep domain and technology capabilities. We help insurers stay ahead with sustained growth and high performance for enhancing stakeholder value and fostering resilient societies. Trusted by over 100 insurers, ValueMomentum is one of the largest services providers exclusively focused on the property and casualty.
ValueMomentum is headquartered in Piscataway, NJ, with state-of-the-art delivery centers in Piscataway, NJ; Hyderabad, Pune, and Coimbatore in India; Toronto in Canada; and London in the United Kingdom.