Role &
Responsibilities :
- Monitor and analyze security alerts from SIEM, EDR, XDR, IDS/IPS, firewalls, and other security monitoring tools.
- Perform Level 2/Level 3 SOC operations including alert triage, investigation, containment, and escalation.
- Conduct in-depth analysis of security incidents, suspicious activities, malware alerts, phishing attempts, and potential breaches.
- Perform threat hunting activities using threat intelligence, MITRE ATT&CK; techniques, and indicators of compromise (IOCs).
- Investigate logs from various sources including endpoints, servers, network devices, cloud platforms, and applications.
- Create detailed incident reports, root cause analysis (RCA), and recommendations for preventing future incidents.
- Manage and respond to security incidents according to defined incident response processes and SLAs.
- Correlate events across multiple security platforms to identify advanced threats and attack patterns.
- Develop and improve detection rules, correlation searches, use cases, and security monitoring dashboards.
- Tune SIEM alerts to reduce false positives and improve detection accuracy.
- Perform malware analysis and suspicious file investigations when required.
- Provide mentorship and technical guidance to junior SOC analysts.
- Participate in 24x7 SOC operations and rotational shifts when required.
Preferred Candidate Profile :
- Bachelors degree in Computer Science, Information Security, Cybersecurity, or related field.
- 5 to 10 years of experience in Security Operations Center (SOC) environments.
- Strong experience handling L2/L3 security incidents and investigations.
- Hands-on experience with SIEM platforms such as:
1.
Splunk Enterprise
Security
2.
Microsoft
Sentinel
- IBM QRadar
- ArcSight
- LogRhythm
- Experience with EDR/XDR solutions such as:
1.
Microsoft
Defender for Endpoint
- CrowdStrike Falcon
- SentinelOne
4.
Palo Alto
Cortex XDR
- Robust understanding of:
- Network security concepts (TCP/IP, DNS, HTTP/HTTPS, VPN, firewalls)
- Windows and Linux operating systems
3.
Active
Directory security
- Cloud security fundamentals (Azure/AWS/GCP)
- Threat intelligence and IOC analysis
- MITRE ATT&CK; framework
- Incident response lifecycle
- Ability to perform:
- Threat hunting
- Log correlation
- Malware investigation
- Phishing analysis
- Digital forensics basics
- Knowledge of security frameworks and standards:
- ISO 27001
- NIST Cybersecurity Framework
- CIS Controls
- PCI-DSS (preferred)
- Relevant certifications preferred:
- CISSP
- CISM
- CEH
- GIAC (GCIH/GCIA/GCFA)
- OSCP
- CompTIA Security
7.
Splunk Certified Cybersecurity
Analyst
8.
Microsoft
Security certifications
📌 Senior Security Operations Center Analyst - Threat Hunting (India)
🏢 Good
📍 India