We are Kocho
Kocho recognise that technology on its own does not deliver change and offers technology adoption services alongside excellent technical consulting to enable our clients to achieve their business goals on their journey to Become Greater.
Our head office is in the heart of London’s West End and provides a comfortable working environment with flexible collaboration spaces that encourage our people to Become Greater with the aim to Do What’s Right.
Kocho is an equal opportunities employer. We make recruitment decisions based on qualifications, skill set and experiences. We consider all suitable candidates regardless of their age, sex, gender reassignment, race, religious beliefs, or lack thereof, marital status, disability or sexual orientation or any other protected characteristic. This is mindset aligns with our company values as we understand that we are Better Together.
Here is the role:
Kocho operate exclusively in the Microsoft Stack. We are experts in everything Microsoft – Azure, Intune, KQL – you name it – it’s in the remit. We expect you to be experienced across the stack with familiarity of the Security Tooling, though you will largely be residing in the Unified Security Operations Platform (formerly Microsoft Defender XDR & Microsoft Sentinel).
In this role, you will be responsible for:
- Ensuring Incident SLAs are met by monitoring our “Work Queue”, which contains high-priority Incidents that must be acknowledged, supported by a Team of Analysts
- Participate on the On-Call Rota (Second Line Escalations Out of Hours)
- Respond to Incidents on a first-line basis where Capacity levels require your intervention
- Be the ‘first responder’ to Escalations from the Analytical Team, before they reach Senior Levels
- Escalate as required, with fully enriched notes and findings into Senior Team Members
- Assist the Analytical Team Lead in taking ownership of Incident Escalations, Incident Response & Client Communications. You may be expected to run an Incident Bridge in the event that the Analytical Team Lead is unavailable.
- Become a master of our Runbook documentation and maintaining an industry standard ‘Wiki’, containing both information and expand our ‘KQL Library’
- Monitor and remediate our industry-leading Phishing & Email Management tool by responding to potential threats reported by our Users and our Clients
- ‘Bridge’ relationships between Service Delivery, Engineering & our Architectural Team by feeding input into the Analytical Team Lead via regular cadences
- Become a Subject Matter Expert in ‘Tuning’ Incidents – raise & review requests through our Azure DevOps Pipelines
- Mentor our Analysts by being a Subject Matter Expert in KQL and all things Microsoft Security
This is what we need from you:
- A degree in Computer Science, Cyber Security or a related field or equivalent and demonstrable experience
- Solid experience in an Analytical Role revolving around Microsoft Defender XDR & Microsoft Sentinel
- Strong knowledge of security best practices, particularly UK based requirements
- Very strong ability to query large data sets using KQL and understand how data is structured in Log Analytics
- Very strong knowledge of the Microsoft Security Stack, particularly everything available in Microsoft Defender XDR
- Very strong written & verbal communication skills – you will be expected to be contribute to high stakes situations with Clients
Would be great if you have:
- Proficiency in certain languages, standards and assemblies/tools such as Python, Bicep, ARM, JSON
- Professional certifications such as AZ-900, SC-300, SC-900, Security+, Network+, A+
- Experience in mentoring junior members of staff