07 Aug
|
Larsen and Toubro (L&T)
|
Chennai
07 Aug
Larsen and Toubro (L&T)
Chennai
Job Purpose
The SOC L1 Analyst serves as the first line of defence in monitoring, identifying, triaging, and escalating security incidents. The analyst continuously monitors security tools and responds to alerts following established procedures. Protect multitenant GPU cloud with defenseindepth, ensuring zerotrust, auditability, and regulatory alignment.
Role Description
Key Responsibilities
Monitor security alerts from SIEM, EDR, IDS/IPS, Firewall, Email Security, and Cloud Security platforms.
Perform initial analysis and triage of security events.
Investigate alerts for false positives and determine potential threats.
Escalate validated incidents to L2 analysts.
Create and maintain incident tickets and documentation.
Maintain SOC runbooks, knowledge base articles, and standard operating procedures.
Execute predefined playbooks and response procedures.
Monitor Kubernetes, Docker, and container runtime security alerts
Monitor threat intelligence feeds and security advisories.
Support vulnerability management and compliance reporting activities.
Participate in shift-based 24x7 SOC operations
Experience & Educational Requirements
Qualifications and Experience
EDUCATIONAL QUALIFICATIONS: (degree, training, or certification required)
BE/B-Tech or equivalent with Computer Science or Electronics & Communication
RELEVANT EXPERIENCE: (no. of years of technical, functional, and/or leadership experience or specific exposure required)
13 years cybersecurity; robust cloud security, zerotrust, and data privacy in regulated environments.
Knowledge of cybersecurity fundamentals.
Understanding of TCP/IP, DNS, HTTP/S, VPN, and networking concepts.
Familiarity with SIEM tools such as Microsoft Sentinel, Splunk, QRadar, ArcSight, or LogRhythm.
Basic understanding of EDR solutions such as Microsoft Defender XDR, CrowdStrike, SentinelOne, or Carbon Black.
Experience analyzing Windows, Linux, and Active Directory logs.
Understanding of MITRE ATT&CK; and Cyber Kill Chain frameworks.
Solid understanding of cloud security, Zero Trust architecture, and data privacy in regulated environments.
Tools / Tech
SIEM/SOAR (Splunk/ELK), EDR/XDR, image scanners (Trivy/Clair), OPA/Gatekeeper, Vault/KMS/HSM, HashiCorp Boundary (or equivalent),Firewalls etc.
Certifications
Security+, SC-200, SC-900, CEH (Associate Level), Microsoft Certified: Security Operations Analyst
📌 Soc Engineer Chennai
🏢 Larsen and Toubro (L&T)
📍 Chennai