31 Jul
|
Tata Consultancy Services
|
Bengaluru
31 Jul
Tata Consultancy Services
Bengaluru
Greetings from TCS!!
Skill: SOC L2/L3
Experience Range: 7-10 years
Interview Date: 31-July-2026 (Friday)
Mode of Interview: Virtual
Interview Location: Bangalore, Hyderabad
Job Specification
- Perform 24x7 monitoring security alerts and events through Google Chronicle SIEM, Crowdstrike EDR, Zsclaer and other available security tools.
- Acknowledge, categorize, and prioritize alerts as per defined incident response procedures.
- Perform initial triage and enrichment using available threat intelligence and playbooks.
- Escalate incidents to L2 & L3 team based on criticality, impact, and scope.
- Track incidents through closure and maintain detailed documentation for all investigations.
- Run queries in the SIEM or CrowdStrike to obtain the relevant information required to make informed decisions
- Assist in health checks and data ingestion validation within the SIEM environment.
- Participate in daily shift handovers and report key metrics and ongoing investigations.
- Perform deep-dive investigation on escalated alerts from L1 and determine true positive incidents.
- Root cause and kill chain investigation to determine the technical vulnerabilities or control weaknesses that gave threat actors access to the system, as well as other factors (such as bad password hygiene or poor enforcement of policies) that contributed to the incident, as well as how far along the kill chain this incident continued
- Understanding of MITRE framework, which will be added to incident cases of severity 3 and above
- Isolating assets – but not fully shutting down or reimaging before analysis has been complete.
- Isolating compromised areas of the network by working with relevant network contacts.
- Pausing or stopping compromised applications or processes
- Deleting damaged or infected files once the investigation has been completed
- Pausing or stopping compromised applications or processes
- Deleting damaged or infected files once the investigation has been completed
- Running antivirus or anti-malware software is determined as a suitable remediation/precautionary measure once the investigation has been completed
- Incidents generated by monitoring endpoints, vulnerability information revealed by scanners, security intelligence feeds, intrusion prevention (IPS), and detection (IDS) systems
- Conduct root cause analysis, impact assessment, and recommend remediation or containment actions.
- Optimize and fine-tune SIEM rules and detection logic to reduce false positives and enhance detection accuracy.
- Collaborate with L3 /L4 engineers and platform teams for advanced analysis and use-case improvements.
- Create and maintain runbooks, detection playbooks, and response workflows for recurring incidents.
- Support threat hunting activities and develop custom dashboards and queries within Google Chronicle.
- Contribute to weekly/monthly incident trend analysis and continuous SOC process improvement.
- Lead SIEM engineering, configuration, and optimization for Google Chronicle and other integrated SIEM platforms.
- Design, develop, and maintain advanced detection use cases mapped to MITRE ATT&CK; framework.
- Integrate recent log sources, build parsers, and enhance data normalization and enrichment pipelines.
- Collaborate with automation teams to implement SOAR-based playbooks for repetitive tasks and false positive reduction.
- Perform use-case performance tuning, correlation logic enhancement, and threat model development.
- Perform advanced threat hunting, retrospective analysis, and detection gap assessments.
- Mentor L1 and L2 teams, review escalated incidents, and validate incident closure quality.
- Drive continuous improvement and SIEM governance activities for overall SOC maturity.
📌 SOC Analyst/ (Bengaluru)
🏢 Tata Consultancy Services
📍 Bengaluru