07 Aug
|
Cybage Software
|
Pune
07 Aug
Cybage Software
Pune
Job Summary:
We are looking for an experienced SOC Analyst to join our security operations team. The ideal candidate should have strong expertise in AWS, Linux, vulnerability management, and penetration testing, along with hands-on experience using tools such as SentinelOne, Microsoft Defender, Azure Sentinel, and Cobalt. The role involves proactive monitoring, vulnerability remediation, and ensuring the overall security and stability of the infrastructure.
Scope of Role
- Incident Response, Administration, Monitoring & SIEM/EDR/IDS-IPS Tuning > 60–70
- %Vulnerability Management & Pentest Coordination > 15–20
- %Hands-on Linux and Windows administration, supporting AWS/Azure cloud security tooling
- Scripting/automation, documentation, and cross-functional collaboration
Must Have Skills
- Robust hands-on experience with SIEM platforms (Microsoft Sentinel or equivalent) alert triage, correlation rule tuning, playbook/automation development
- Strong Hands-on experience with EDR/XDR tools (Microsoft Defender for Endpoint, SentinelOne, Crowdstrike) investigation, containment, and remediation of endpoint threats
- Working knowledge of IDS/IPS administration and tuning
- Support for proactive threat hunting activities, including consuming threat intelligence feeds and enriching alerts with IOCs/TTPs
- Practical experience with vulnerability identification, tracking, and remediation.
- Exposure to offensive security tools (Burp Suite, NMAP, OWASP ZAP, SQLMap, etc.)
- Exposure to phishing simulation / security awareness platforms (KnowBe4, Proofpoint, etc.)
- Solid Linux and Windows administration skills
- Willingness to work in a 24×7 rotational SOC environment
- Good to have : PowerShell, python, bash scripting for automation and investigation support
Roles & Responsibilities
- Monitor security alerts and infrastructure around the clock, triage, investigate, and respond to incidents across SIEM, EDR, and IDS/IPS platforms
- Implement, tune and maintain detection rules, correlation logic, and automation playbooks to reduce false positives and improve response times
- Monitor cloud security posture and identity/DLP alerts (Wiz, AWS GuardDuty, Entra ID, Purview) alongside core SIEM/EDR monitoring
- Perform Linux and Windows system administration tasks in support of security tooling and incident response
- Write and maintain PowerShell, Python, and Bash scripts to automate investigation, remediation, and reporting tasks
- Track vulnerability exposure across endpoints, and coordinate remediation with Cloud, Engineering and IT teams
- Perform internal vulnerability scans and web application/network assessments as required, using tools such as NMAP, Burp Suite, OWASP ZAP, and SQLMap.
- Maintain documentation and playbooks to ensure consistent coverage across shifts
- Collaborate cross-functionally and deliver post-incident and post-assessment reports and recommendations.
📌 SOC Specialist (Pune)
🏢 Cybage Software
📍 Pune