05 Aug
|
HCL Technologies
|
Bengaluru
05 Aug
HCL Technologies
Bengaluru
Track Lead - Security Investigations, SIEM
Experience: 5 to Not Available years
Location: Bengaluru, India
Skills: Microsoft Sentinel, Splunk, QRadar, Elastic, Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, TCP/IP, DNS, HTTP/S, VPN, Active Directory, Entra ID, Azure AD, Windows Server, Linux, Azure, Log analysis, Process behavior, Memory artifacts, IoC analysis, MITRE ATT&CK;, TTP analysis, IoC management, IDS/IPS, Firewalls, CASB, DLP, Secure web gateways, PowerShell, Python, AZ-500, SC-200, CEH, CompTIA Security+
Job Summary
Professional Profile – SOC Level 3 Analyst (5+ years experience) Cybersecurity specialist with over three years of experience in advanced security monitoring, incident investigation, and coordination with response teams. Skilled in handling complex alerts, optimizing detection rules and playbooks, and strengthening the internal SOC’s security posture. Highly analytical, procedure-oriented, and effective in resolving incidents in demanding operational environments.
Key Responsibilities
Analyze, investigate, and escalate Level 3 security incidents across SIEM, EDR, network, and cloud environments.
Perform deep-dive investigations (root cause analysis, event correlation, artifact analysis, forensic timelines).
Validate, tune, and enhance SIEM detection rules, use cases, and dashboards.
Execute and enrich automated response workflows in SOAR platforms.
Coordinate response actions with Infrastructure, Network, Endpoint, and Red Team/Offensive Security teams.
Monitor emerging threats and correlate them using threat intelligence feeds and frameworks.
Document incidents, actions taken, lessons learned, and propose continuous improvements.
Support Level 2 analysts with complex or recurring alert patterns.
Participate in incident response simulations (tabletop and technical exercises).
Skill Requirements
Technical Requirements
Solid knowledge in:
SIEM: Microsoft Sentinel, Splunk, QRadar, Elastic, or similar.
EDR/XDR: Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, etc.
Protocols & Technologies: TCP/IP, DNS, HTTP/S, VPN, Active Directory, Entra ID/Azure AD.
Operating Systems: Windows Server, Linux, and cloud environments (especially Azure).
Basic forensics: Log analysis, event review, process behavior, memory artifacts, IoC analysis.
Threat intelligence: MITRE ATT&CK;, TTP analysis, IoC management.
Security tools: IDS/IPS, firewalls, CASB, DLP, secure web gateways.
Nice to have:
Scripting knowledge (PowerShell, Python).
Relevant certifications: AZ-500, SC-200, CEH, CompTIA Security+, or similar.
Other Requirements
Other Requirement : Security Event Investigation, Technical solution implementation-SIEM
Job Summary : Security Event Investigation, Technical solution implementation-SIEM
Job Responsibilities : Security Event Investigation, Technical solution implementation-SIEM
Skill Requirement : Security Event Investigation, Technical solution implementation-SIEM
Job Role : SME - Security Analysis, SIEM
📌 Track Lead Security Investigations, SIEM (Bengaluru)
🏢 HCL Technologies
📍 Bengaluru