Role & responsibilities
- 7-10 years of experience in cyber with at least 5+ years in SOC Operations, Security Monitoring, Incident Response, SIEM Administration, or Cyber Security Operations.
- Hands-on experience with Splunk Enterprise Security, Splunk Core, and SIEM Operations.
- Strong experience in advanced log analysis, event correlation, alert investigation, and threat detection.
- Experience in managing and supporting SOAR-related activities and security automation workflows.
- Practical knowledge of threat intelligence platforms and application of threat intelligence to detection and response.
- Good understanding of MITRE ATT&CK; Framework, Cyber Kill Chain, and Threat Hunting methodologies.
- Ability to identify exploitation techniques, vulnerabilities, and security control gaps.
- Solid technical communication skills and experience handling incident escalation and stakeholder reporting.
- Experience integrating and monitoring security events from EDR, Firewalls, IDS/IPS, WAF, IAM, Cloud Platforms, Databases, and Applications.
Preferred candidate profile
- Candidate with experience in preparation of technical proposals, RFP responses, compliance matrices, and solution documentation would be preferred.
Experience in cybersecurity engagements for Government, PSU, Critical Infrastructure and Defense would be preferred
📌 SOC Security Analyst (Splunk) (Noida)
🏢 EY
📍 Noida