SOC Threat Hunting & Advanced Analysis (Gurugram)

SOC Threat Hunting & Advanced Analysis (Gurugram)

02 Aug
|
Codec Networks
|
Gurugram

02 Aug

Codec Networks

Gurugram

The Tier 3 SOC Analyst is the senior technical authority on the analysis floor at Codec Networks Pvt. Ltd. The role combines proactive, hypothesis-driven threat hunting with deep investigation of the most complex, novel or high-impact incidents escalated from Tier 2.

The T3 analyst develops and validates detection logic, reconstructs sophisticated attack chains, reverse-engineers suspicious behaviour, operationalises threat intelligence into hunts, and mentors T1/T2 analysts. Working primarily on a day pattern with on-call coverage, the role requires expert command of SIEM, EDR and network forensics, strong scripting ability, and the maturity to drive improvements to the SOC's detection posture and playbooks.

Position Details

Reports To

- Shift Lead / SOC Manager

Direct Reports

- None

Department

- Security Operations Centre (SOC) – Codec Networks Pvt. Ltd.

Employment Type

- Full-time

Work Pattern

- 24×7×365 rotating shifts, including nights, weekends, and public holidays.

Location / Work Mode

- Delhi/Gurugram
- On-site at the SOC facility.
- Shift-based role; remote work is not available for Tier 1 (SOC Analyst L1).

Seniority

- Entry Level (Grade: SOC-1)

Indicative CTC (INR)

- As per industry best standards.

Technical Skills

Threat Hunting

- Specific Skills Required: Hypothesis-driven hunting, behavioural analytics, anomaly detection
- Proficiency Level: Expert

Malware Analysis

- Specific Skills Required: Full static/dynamic analysis, reverse engineering, C2 identification
- Proficiency Level: Expert

MITRE ATT&CK;

- Specific Skills Required: Advanced TTP correlation, adversary emulation, detection gap analysis
- Proficiency Level: Expert

Scripting / Automation

- Specific Skills Required: Python, PowerShell, YARA rules, Sigma rules development
- Proficiency Level: Advanced

Memory Forensics

- Specific Skills Required: Volatility, WinPmem, memory artefact extraction and analysis
- Proficiency Level: Advanced

Threat Intelligence

- Specific Skills Required: Intelligence integration into hunt hypotheses, adversary profiling
- Proficiency Level: Advanced

Detection Engineering

- Specific Skills Required: Writing SIEM detection rules (SPL/KQL),



tuning correlation logic
- Proficiency Level: Advanced

Purple Team

- Specific Skills Required: Adversary emulation, Atomic Red Team, attack simulation coordination
- Proficiency Level: Intermediate

Soft Skills

- Attention to detail and pattern recognition under high alert volume
- Clear and concise written documentation skills
- Ability to remain calm and focused during high-pressure P1 situations
- Effective shift handover communication
- Willingness to escalate early rather than over-investigate at T1 level

Soft Personality Attributes

- Conscientious & consistent — brings the same diligence to alert #500 as to alert #1.
- Calm under pressure — stays composed during alert storms and P1 escalations.
- Detail-oriented — notices the small anomaly others scroll past.
- Dependable & punctual — reliable shift attendance is critical to 24×7 cover.
- Humble & coachable — escalates early rather than over-reaching, and acts on feedback.
- Genuinely curious — interested in how attacks work and eager to grow.

Technical Deliverables

Triaged Alert Tickets

- Description: Fully triaged, classified, and documented alert tickets in the ITSM tool with severity, asset context, and rationale.
- Cadence: Every shift

Escalation Handover Notes

- Description: Structured escalation packages for Tier 2 (T2) containing IOCs, enrichment details, and initial findings.
- Cadence: Per confirmed true positive

Shift Handover Report

- Description: Written handover covering open alerts, ongoing incidents, and pending actions.
- Cadence: Per shift rotation

False-Positive Feedback

- Description: Documented false-positive (FP) tuning recommendations submitted to the SIEM Engineer.
- Cadence: Weekly or as identified

Playbook Execution Records

- Description:



Evidence of pre-approved SOAR playbooks executed, including outcomes and actions taken.
- Cadence: Per eligible alert

SLA & Quality Metrics

- Description: Individual contribution to alert acknowledgement, triage performance, and false-positive accuracy KPIs.
- Cadence: Weekly / Monthly

Minimum Qualification & Industry Experience

Education

- Minimum (Must-Have): Bachelor's degree in Computer Science, Information Technology, Electronics, or any discipline with a recognized cybersecurity certification or diploma.
- Preferred (Strong Plus): B.Tech, B.E., BCA, B.Sc. (Computer Science), or a Postgraduate Diploma in Cyber Security.

Total Experience

- Minimum (Must-Have): 0–2 years.
- Preferred (Strong Plus): 1–2 years of experience in an IT Helpdesk, Network Operations Centre (NOC), or SOC internship.

Security / SOC Experience

- Minimum (Must-Have): 0–1 year; internship, laboratory, or academic SOC exposure is acceptable.
- Preferred (Strong Plus): 6–12 months of hands-on SIEM alert monitoring experience.

Industry / Sector Exposure

- Minimum (Must-Have): No mandatory industry experience; exposure to any IT operations environment is acceptable.
- Preferred (Strong Plus): Experience in an MSSP, multi-tenant environment, BFSI, IT/ITeS, or telecom monitoring.

Workplace Scale

- Minimum (Must-Have): Familiarity with enterprise IT concepts such as Active Directory (AD), DNS, email systems, and endpoints.
- Preferred (Strong Plus): Experience with 24×7 monitoring of enterprise environments containing 500+ endpoints.

Certifications

- Minimum (Must-Have): CompTIA Security+ certification within six months of joining.
- Preferred (Strong Plus): CySA+, CEH, Microsoft SC-200, or Splunk Core User certification.

Language

- Minimum (Must-Have): Professional proficiency in written and spoken English.
- Preferred (Strong Plus): Proficiency in one or more additional Indian languages to support regional client engagements.

Eligibility

- Minimum (Must-Have): Willingness and ability to work permanent rotating night shifts.
- Preferred (Strong Plus): Immediate joiner.

📌 SOC Threat Hunting & Advanced Analysis (Gurugram)
🏢 Codec Networks
📍 Gurugram

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: soc threat hunting & advanced analysis (gurugram) / gurugram

Subscribe to this job alert:

Get the latest job offers by email for: soc threat hunting & advanced analysis (gurugram) / gurugram