Job Description SOC L3 Analyst or Team Lead
Location : Noida
Rotational shift
Experience : 10 -16 years
Please share your profile at
[email protected] or call at (phone hidden)
Key Responsibilities
Oversight of L1 Operations
• Review and validate L1 alert triage and closure decisions on a sampling/audit basis to ensure accuracy and consistency
• Coach L1 analysts in real time on investigation technique, tooling, and escalation judgment
• Own the L1L2/L3 escalation queue; ensure escalated cases are picked up and worked within SLA
• Identify recurring L1 errors or knowledge gaps and feed them into training plans and playbook updates
Investigation & Response
• Lead deep-dive investigations for escalated and high-severity alerts across endpoint, network, identity, and cloud telemetry
• Perform root cause analysis, timeline reconstruction, and scoping of confirmed incidents
• Drive containment and remediation actions in coordination with IR, IT, and asset owners
• Author clear, defensible incident reports and post-incident reviews
Detection Engineering & Tuning
• Identify false-positive patterns and detection gaps from L1/L3 casework; write or tune correlation rules and detections (SIEM: Google SecOps/Chronicle, Splunk, or Devo or Any other)
• Partner with detection engineering/content team on new use cases derived from investigation findings
• Maintain and improve SOPs, runbooks, and playbooks used by L1
Process & Quality Assurance
• Conduct periodic quality audits of closed tickets against SOC investigation standards
• Track and report on quality metrics (mean time to triage/escalate, false-positive rate, reopened-ticket rate)
• Ensure chain-of-custody and evidence-handling standards are followed on all investigations
• Support shift handover quality verify handover notes are complete and actionable
Mentorship & Enablement
• Act as the senior technical mentor for the L1 team; run knowledge-sharing sessions
• Contribute to onboarding and skills-development curriculum
• Be the go-to escalation point during shift for ambiguous or high-pressure alerts
Required Qualifications
• 10+ relevant years in a SOC/security operations setting, with at least 3+ years performing L2/L3-level investigation or incident response
• Solid hands-on experience with a SIEM platform (Splunk, Google SecOps/Chronicle, Devo, or equivalent) including query authoring and correlation rule tuning
• Solid understanding of endpoint (EDR — e.g., SentinelOne, CrowdStrike), network security (e.g., Palo Alto), and identity/access telemetry
• Working knowledge of the MITRE ATT&CK; framework and structured investigation methodology
• Experience with incident documentation, RCA, and post-incident reporting
• Strong ability to review and coach junior analysts’ work without owning every ticket personally
Preferred Qualifications
• Prior team lead / shift lead experience in a SOC
• Familiarity with SOAR platforms and automation/playbook design
• Exposure to cloud security monitoring (AWS/Azure/GCP)
• Experience operating in a global/24x7 SOC model with shift handovers
Success Metrics for the Role
• Improvement in mean time to detect/escalate/contain
• Audit pass rate on investigation quality reviews
• Measurable uplift in L1 team capability (fewer repeat coaching items quarter over quarter)
Thanks
Salma Saifi
📌 Security Operations Center Manager (Noida)
🏢 Cms IT Services
📍 Noida