06 Aug
|
Simfluent
|
Noida
Role Overview
We are seeking a highly technical and proactive Sr.
Security Operations
Analyst to join our Information Security team. In this role you will engineer and mature our security operations infrastructure — designing automated playbooks, tuning advanced telemetry across SIEM, EDR, and cloud environments, and leading high-severity incident containment. As a senior member of the team, you will define triage standards and elevate the technical capability of the wider SOC. n Responsibilities
Detection engineering: Architect and optimize real-time detection engineering playbooks across SIEM, EDR, and cloud security platforms to minimize false positives, accelerate triage, and scale threat-hunting capability.
Investigation: Investigate suspicious activity, correlate findings across data sources, and document explicit, timely case notes for each alert or incident.
Incident command: Lead the response lifecycle for high-severity incidents as primary investigator or incident commander, ensuring seamless coordination and technical handoff across cross-functional teams.
Containment: Execute containment actions under established playbooks, including endpoint isolation, disabling compromised accounts, and blocking malicious indicators.
Threat hunting: Research indicators of compromise and apply threat intelligence to identify anomalous behavior.
Rule tuning: Tune detection rules and use cases to reduce false positives and close visibility gaps, in coordination with engineering.
Email threats: Investigate and remediate email-based threats such as phishing and business email compromise, from both user submissions and automated detection.
Continuous improvement: Contribute to post-incident reviews and metrics reporting — MTTD, MTTR, alert volume,
and false-positive rate — to support ongoing SOC maturity.
Currency: Stay current on emerging threats, attacker TTPs, and industry frameworks such as MITRE ATT&CK.; Requirements
SIEM platforms
Splunk
Microsoft Sentinel
QRadar
EDR platforms
CrowdStrike
Microsoft Defender for Endpoint
SentinelOne
Windows operating systems
Linux operating systems
TCP/IP
DNS
Firewalls
Network proxies
Incident response
Threat hunting
Detection engineering
Log analysis
MITRE ATT&CK; framework
Phishing investigation
Business email compromise
Written communication
Case documentation Preferred Skills
AWS
Azure
GCP
Cloud security
SOAR platforms
Python
PowerShell
KQL
SPL
Security automation
Playbook development Qualifications
4–6 years of IT or security experience, including hands-on exposure to a SOC, security help desk, or systems administration environment
3+ years monitoring or investigating alerts using a SIEM (e.g., Splunk, Sentinel, QRadar) and an EDR platform (e.g., CrowdStrike, Defender for Endpoint, SentinelOne)
Working knowledge of Windows and Linux operating systems, including common attack surfaces and log sources such as event logs, auth logs, and process telemetry
Foundational understanding of networking concepts (TCP/IP, DNS, proxies, firewalls) and the protocols relevant to intrusion detection
Strong attention to detail, sound judgment under time pressure, and clear written communication for case documentation and shift handoffs
Ability to work effectively in a 24/7 SOC rotation, including scheduled shifts and periodic on-call coverage
Bachelor's degree in Cybersecurity, Information Technology, or a related field — or equivalent hands-on experience
Foundational certifications such as CompTIA Security+ or CySA+ are expected; progress toward GIAC (GCIH, GFACT) or similar is a plus n
📌 Sr. Security Operations Analyst (Noida)
🏢 Simfluent
📍 Noida