Sr Analyst (Chennai)

Sr Analyst (Chennai)

05 Aug
|
HCL Technologies
|
Chennai

05 Aug

HCL Technologies

Chennai

Sr Analyst

Experience: 3 to 6 years

Location: Chennai, India

Skills: Microsoft Sentinel, SIEM tools, ArcSight, Splunk, QRadar, EDR, Firewall, AD, Cloud logs, MITRE ATT&CK; framework, Cyber Kill Chain, phishing, malware, ransomware, insider threats, Microsoft Defender, CrowdStrike, Carbon Black, Qualys, Nessus, KQL, SPL, TCP/IP, DNS, HTTP, VPN, Windows fundamentals, Linux fundamentals

Job Summary
The SOC Operations Analyst L2 is responsible for monitoring and analyzing security alerts using tools like Microsoft Sentinel. The role includes investigating incidents, identifying real threats, and supporting response and remediation activities. The analyst works on alerts escalated from L1, performs log analysis, and helps improve detection by fine-tuning rules. They also support threat hunting, automation, and maintain proper documentation and reports. This role requires good knowledge of SIEM tools, security logs, and common cyber threats, along with close coordination with internal security and IT teams.

Duties and Responsibilities
? Threat Monitoring & Analysis
Monitor security alerts from SIEM tools (Sentinel, ArcSight, Splunk, QRadar)
Perform in-depth analysis of escalated incidents (L1 → L2)
Validate true positives and eliminate false positives

? Incident Investigation & Response
Conduct root cause analysis (RCA) for security incidents
Perform log correlation across multiple sources (EDR, Firewall, AD, Cloud logs)
Support incident containment and remediation actions

? Use Case Tuning & Optimization
Fine-tune SIEM correlation rules and alerts
Reduce noise and improve detection accuracy
Map detections to MITRE ATT&CK; framework

? Threat Hunting (Proactive)
Perform proactive threat hunting using SIEM, EDR, and threat intelligence




Identify hidden or advanced threats not detected by rules
Develop hypotheses-based hunting scenarios

? Automation & Playbooks
Support SOAR playbook execution (Sentinel Logic Apps, etc.)
Assist in developing automation for repetitive tasks
Integrate SIEM with ticketing systems (ServiceNow)

? Reporting & Documentation
Document incidents, findings, and recommendations
Prepare incident reports, dashboards, and metrics
Maintain SOPs, runbooks, and knowledge base

? Collaboration
Work closely with L1 analysts, L3 engineers, and IR teams
Coordinate with IT teams for remediation actions
Support audits and compliance activities

Key Responsibilities
? Threat Monitoring & Analysis
Monitor security alerts from SIEM tools (Sentinel, ArcSight, Splunk, QRadar)
Perform in-depth analysis of escalated incidents (L1 → L2)
Validate true positives and eliminate false positives

? Incident Investigation & Response
Conduct root cause analysis (RCA) for security incidents
Perform log correlation across multiple sources (EDR, Firewall, AD, Cloud logs)
Support incident containment and remediation actions

? Use Case Tuning & Optimization
Fine-tune SIEM correlation rules and alerts
Reduce noise and improve detection accuracy
Map detections to MITRE ATT&CK; framework

? Threat Hunting (Proactive)
Perform proactive threat hunting using SIEM, EDR, and threat intelligence




Identify hidden or advanced threats not detected by rules
Develop hypotheses-based hunting scenarios

? Automation & Playbooks
Support SOAR playbook execution (Sentinel Logic Apps, etc.)
Assist in developing automation for repetitive tasks
Integrate SIEM with ticketing systems (ServiceNow)

? Reporting & Documentation
Document incidents, findings, and recommendations
Prepare incident reports, dashboards, and metrics
Maintain SOPs, runbooks, and knowledge base

? Collaboration
Work closely with L1 analysts, L3 engineers, and IR teams
Coordinate with IT teams for remediation actions
Support audits and compliance activities

Skill Requirements
Core Skills
Hands-on experience with SIEM tools (Sentinel / ArcSight / Splunk / QRadar)
Robust understanding of logs: Windows Event Logs, Syslog / Firewall logs, Cloud logs (Azure/AWS/GCP)
Detection & Security Knowledge
MITRE ATT&CK; framework, Cyber Kill Chain, Threat vectors: phishing, malware, ransomware, insider threats
Tools & Technologies
EDR tools (Microsoft Defender, CrowdStrike, Carbon Black), Email security tools, Vulnerability tools (Qualys, Nessus)
Querying & Analysis
KQL / SPL / Query languages, Log correlation and pattern analysis
Systems & Networking
Networking basics (TCP/IP, DNS, HTTP, VPN), Windows & Linux fundamentals

Other Requirements
Experience Requirements
3–6 years in SOC / Security Operations
Experience handling P2/P3 incidents independently
Exposure to incident response and threat hunting

Education & Certifications
Bachelor’s degree in IT / Cybersecurity
Preferred certifications: SC-200 (Microsoft Security Operations), CEH / Security+, GIAC / CySA+ (optional)

📌 Sr Analyst (Chennai)
🏢 HCL Technologies
📍 Chennai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: sr analyst (chennai) / chennai

Subscribe to this job alert:

Get the latest job offers by email for: sr analyst (chennai) / chennai