Soc Analyst 1 (Hyderabad)

Soc Analyst 1 (Hyderabad)

07 Aug
|
Amerisource Solutions
|
Hyderabad

07 Aug

Amerisource Solutions

Hyderabad

Role & responsibilities :

MGT is a leading provider of technology and advisory solutions serving state, local, and education government agencies (SLED) across the United States. Through client partnerships, MGTs almost 1,200 employees impact communities for positive by managing and securing critical networks, solving complex human capital and fiscal problems, elevating education systems, and advancing equity as a performance imperative. MGT partners with thousands of agencies as a trusted advisor delivering solutions that improve technology, operational, and economic performance to help communities thrive.

Founded in 1975, MGT initiated an ambitious restart in 2016, broadening the solutions portfolio to provide the most specialized solutions, tackling the most mission-critical problems that live at the top of the public agency leadership agenda. MGT drives over 20% compound annual organic growth and utilizes programmatic mergers and acquisitions to grow capabilities, attract top talent, and accelerate growth scale. Since 2020, MGT has successfully completed 13 acquisitions, driving over 60% compound annual inorganic growth.

Celebrating its 50th year in 2025, the firm attracts exceptional talent and empowers them to exceed client expectations as they navigate the dynamic demands of the clients we serve. Hear more about MGTs culture in the words of our employees.

Key Responsibilities

- Monitor, triage, investigate, and correlate alerts generated from SIEM, EDR, email security, identity, cloud, and network security platforms.
- Analyze security events and determine the legitimacy, severity, and potential impact of identified threats.
- Perform initial investigation and evidence collection for suspected security incidents and document findings accurately.
- Utilize SIEM platforms such as Rapid7 InsightIDR, Microsoft Sentinel, Splunk,



and other monitoring tools to identify malicious activity.
- Execute approved SOAR playbooks and containment actions in accordance with client requirements and established procedures.
- Escalate actionable security incidents to SOC L2/L3 analysts following defined escalation criteria and incident response processes.
- Monitor threat intelligence feeds, emerging vulnerabilities, zero-day threats, and active attack campaigns impacting client environments.
- Investigate phishing, malware, suspicious login activity, account compromise indicators, privileged access changes, and anomalous user behavior.
- Perform log analysis across various data sources, including:
- Active Directory
- Microsoft 365
- Azure
- DNS
- Firewalls
- VPNs
- Endpoint Security Tools
- Proxy/Web Security Solutions
- Network Devices

- Create client-facing investigation summaries, escalation reports, and incident notifications.
- Maintain detailed case documentation within ticketing, case management, and SOC platforms.
- Assist in developing, reviewing, and maintaining SOC playbooks, runbooks, and standard operating procedures.
- Support monthly operational reviews, security reporting activities, and client presentations as required.
- Update and maintain client documentation, asset inventories, escalation contacts, and knowledge base articles in SharePoint and related systems.
- Participate in knowledge transfer sessions, training initiatives, and continuous process improvement activities.




- Adhere to shift schedules and support a 24x7 SOC operational model.

Preferred candidate profile

- 2-4 years of experience in a Security Operations Center (SOC), Cybersecurity Operations, or Information Security role.
- Hands-on experience working with SIEM platforms such as:
- Rapid7 InsightIDR
- Microsoft Sentinel
- Splunk
- QRadar

- Familiarity with SOAR platforms and security automation workflows.
- Understanding of common cybersecurity attack techniques, tactics, and procedures (TTPs).
- Knowledge of:

- Windows Security Events
- Active Directory
- Microsoft 365 Security
- Azure Security
- Networking Fundamentals
- DNS
- TCP/IP
- VPN Technologies

- Experience investigating phishing, malware, suspicious authentications, insider threat indicators, and endpoint security alerts.
- Ability to analyze and interpret security logs from multiple data sources.
- Strong analytical, troubleshooting, and decision-making skills.
- Excellent written and verbal communication skills.
- Ability to create clear and concise incident reports and client communications.
- Experience working in a 24x7 shift-based SOC environment.
- Understanding of MITRE ATT&CK; framework and security incident response lifecycle is preferred.

Preferred Certifications

One or more of the following certifications are preferred:

- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Certified Ethical Hacker (CEH)
- CompTIA Security+
- Rapid7 InsightIDR Administrator (preferred)

Key Competencies

- Security Monitoring & Incident Triage
- Threat Detection & Analysis
- Rapid7 InsightIDR Operations
- Microsoft Sentinel Operations
- Log Analysis & Investigation
- Incident Escalation Management
- Threat Intelligence Utilization
- Documentation & Reporting
- Client Communication
- Team Collaboration
- Continuous Learning & Adaptability

📌 Soc Analyst 1 (Hyderabad)
🏢 Amerisource Solutions
📍 Hyderabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: soc analyst 1 (hyderabad) / hyderabad

Subscribe to this job alert:

Get the latest job offers by email for: soc analyst 1 (hyderabad) / hyderabad