Job Summary
We are seeking a Senior SOC Analyst (Tier 3) to join our global security operations team. This role serves as the in-house escalation point for our Managed Detection and Response (MDR) provider, leads complex investigations, and drives incidents through to resolution. You will work with the MDR lead during your shift to validate triage quality, tune detections, and ensure our environment is well-defended against evolving threats. In addition to core SecOps responsibilities, this role will support global security projects and audits (such as NIST, ISO, and TISAX) by providing operational evidence, control validation, and audit narratives.
Key Responsibilities
1. Escalated Incident Response & Investigation
- Serve as the internal escalation point for incidents escalated by the MDR provider.
- Lead containment, eradication, and recovery activities for confirmed incidents.
- Conduct deep-dive investigations, root cause analyses, and forensic reviews across endpoint, identity, network, and cloud environments.
- Work with the Infrastructure team and regional Security leads to coordinate cross-functional responses and communicate status updates to the SOC Manager and leadership.
- Produce clear, well-documented investigation reports and technical documentation in English and Chinese.
2. MDR Oversight & Governance
- Review MDR escalations for quality, accuracy, and completeness; provide feedback and challenge false positives or missed context.
- Partner with the SOC Manager on MDR QBRs, SLA reviews, and service tuning.
- Identify coverage gaps between the MDR scope and our environment, and drive remediation.
3. Threat Hunting & Detection Engineering
- Perform proactive, hypothesis-driven threat hunts using KQL in Microsoft Sentinel and Defender XDR.
- Develop and tune custom detection rules, analytics, and correlation logic in Sentinel.
4. Threat Intelligence & Vulnerability Correlation
- Assist operationalize threat intelligence (IOCs, TTPs, threat actor profiles) into detections and hunts.
5. Global Security Projects & Audit Support
- Support ad-hoc global security projects as directed by the SOC Manager and security leadership.
- Provide operational evidence, log extracts, and control validation for NIST, ISO, and TISAX audit narratives.
- Partner with regional GRC, IT, and business stakeholders on security initiatives.
- Participate in tabletop exercises, purple team engagements, and audit walkthroughs.
6. Reporting, Metrics & Continuous Improvement
- Contribute to SOC reporting MDR performance, incident trends, MTTD/MTTR, and top threats for the SOC Manager and executive stakeholders.
- Maintain accurate documentation of investigations, evidence, and chain of custody.
- Drive continuous improvement of SOC playbooks, runbooks, and response procedures.
- Mentor junior team members and share knowledge across the security operations team.
Required Qualifications
- 3+ years of experience in a SOC or security operations role, with demonstrated experience handling escalated incidents and complex investigations.
- Hands-on experience with Microsoft Sentinel and Microsoft Defender XDR (Endpoint, Identity, Cloud).
- Solid understanding of TCP/IP, DNS, HTTP/S, and common network protocols.
- Solid understanding of Windows, Linux, and macOS internals and logging.
- Cloud security fundamentals (Azure, M365; AWS/GCP a plus).
- Identity and access management concepts (Entra ID / Active Directory).
- Working knowledge of the MITRE ATT&Attack framework and the cyber kill chain.
- Professional fluency (written and verbal) in English and Chinese (Mandarin).
- Strong analytical, problem-solving, and communication skills.
- Self-starter who can operate effectively with minimal supervision.
- Ability to collaborate with global teams across time zones, with willingness to participate in an after-hours on-call rotation for major incidents.
- Willingness to travel for annual team functions and meetings.
Preferred Qualifications
- 5+ years of experience in security operations, with 2+ years in a senior, Tier 2, or Tier 3 escalation capacity.
- Digital forensics fundamentals (memory, disk, and cloud artifact analysis).
- Exposure to SOAR platforms and automated playbook development.
- Scripting proficiency (PowerShell, Python, or Bash) for automation and log analysis.
- Familiarity with threat intelligence platforms (TIPs) and IOC management.
- Incident command or bridge-lead experience in a mid-to-large enterprise environment.
- Bachelor degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent practical experience).
Preferred Certifications
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- GIAC (GCIH, GCIA, GCFA, or GCFE)
- OSCP (OffSec Certified Professional)
- CCNA (Cisco Certified Network Associate)
- CISSP (Certified Information Systems Security Professional)
About YAGEO Group
YAGEO Group is a global leader in electronic components, operating across multiple brands, regions, and manufacturing footprints. As part of our continued transformation and growth in Asia, we are strengthening regional leadership to ensure scalable, high-performing, and customer-centric operations.