03 Aug
|
SNP Cloud Technologies
|
Telangana
03 Aug
SNP Cloud Technologies
Telangana
Cybersecurity Engineer :
Job Summary:
Looking for a SOC Engineer (L2/L3) with 23 years of experience in Security Operations. Candidate should have hands-on experience with the Microsoft Security stack, particularly Microsoft Sentinel and Microsoft Defender XDR, along with solid incident investigation, threat hunting, and log analysis skills. The role involves monitoring, investigating, and responding to security incidents while continuously improving detection capabilities.
Key Responsibilities:
Monitor, investigate, and respond to security alerts and incidents using Microsoft Sentinel and Microsoft Defender XDR.
Perform triage, root cause analysis, and recommend remediation for security incidents.
Conduct threat hunting using KQL and Microsoft security tools.
Analyze logs from endpoints, identity, email, cloud, and network devices.
Create and tune analytics rules, watchlists, and automation rules in Microsoft Sentinel.
Work with playbooks and SOAR automation to improve incident response.
Collaborate with L1 analysts, engineering teams, and customers during incident investigations.
Prepare incident reports, documentation, and knowledge base articles.
Required Skills:
2 - 3 years of experience in a SOC or Cyber Security Operations role.
Hands-on experience with Microsoft Sentinel and Microsoft Defender XDR.
Familiarity with Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud.
Solid knowledge of incident response, threat detection, and log analysis.
Good understanding of SIEM, XDR, EDR, and SOAR concepts.
Experience writing and troubleshooting KQL queries.
Knowledge of Windows, Linux, Active Directory, Microsoft Entra ID, and Microsoft 365 security.
Understanding of networking fundamentals, common attack techniques, and the MITRE ATT&CK; framework.
Basic scripting knowledge in PowerShell or Python is an advantage.
Positive to Have
Experience with other SIEM platforms such as Splunk, QRadar, ArcSight, or similar tools.
Knowledge of Azure Monitor, Log Analytics Workspace, and Azure security services.
Familiarity with threat intelligence platforms, IOC analysis, malware analysis, or vulnerability management.
Exposure to phishing investigations and email security.
Preferred Certifications:
SC-200 Microsoft Security Operations Analyst
SC-900 Microsoft Security, Compliance, and Identity Fundamentals
Security+ or CEH
📌 Cyber Security Engineer Telangana
🏢 SNP Cloud Technologies
📍 Telangana