A public-sector digital services organisation is operating a security function that monitors SIEM and EDR events and protects Office 365 identities, devices and data. This mid-level Security Operations Analyst role combines incident qualification and response support with daily administration of Microsoft Purview, Azure, Microsoft Entra ID, and related MDM and MAM policies.
The mission
The security function receives events from SIEM and EDR tooling and evaluates whether activity indicates an incident, vulnerability or attack. Its Microsoft environment includes Azure, Microsoft Active Directory, Microsoft Entra ID, Office 365, SharePoint and Windows Server, with ServiceNow supporting operational tracking. This work protects user accounts and organisational data while giving the organisation a repeatable way to detect, prioritise and follow up security risks.
At medior level, you will analyse and qualify events, assess incident severity, notify relevant stakeholders and escalate cases according to established procedures. You will support investigations, containment, remediation and risk mitigation, and recommend both immediate corrective measures and longer-term controls. You will also serve as the operational reference for Microsoft Purview, contributing to its design, evolution and daily management, alongside projects covering data classification and data-loss prevention.
Your responsibilities
- Identify, analyse and qualify security events from SIEM and EDR sources, separating actionable incidents from routine activity.
- Assess incident severity, notify stakeholders, document decisions and maintain traceable follow-up in ServiceNow.
- Support security investigations and incident handling through containment, remediation and risk mitigation.
- Recommend immediate corrective actions and longer-term controls for vulnerabilities, threats and attack patterns.
- Shape the collection and management of security events, and improve procedures for monitoring threats and vulnerabilities.
- Manage Microsoft Purview as the operational reference, supporting its design, evolution, daily administration and data-protection projects.
Your profile
Essential skills
- Bring medior-level professional experience in security operations, event analysis, incident handling or a closely related function.
- Interpret SIEM and EDR alerts and make consistent decisions on severity, notification and escalation.
- Work confidently with Azure, Microsoft Active Directory (AD) and Microsoft Entra ID in an enterprise Microsoft environment.
- Administer Office 365, SharePoint and Windows Server, with attention to identity, access and security controls.
- Manage MDM and MAM policy controls and understand their role in protecting devices, applications and organisational data.
- Use PowerShell scripting to automate administration, validation checks and repeatable security tasks.
- Operate Microsoft Purview for data classification, information protection and data-loss prevention, and use ServiceNow for operational follow-up.
- Communicate clearly during investigations, document findings and coordinate remediation with infrastructure and application teams.