11 Aug
|
Sveltetech Technologies
|
Gurugram
11 Aug
Sveltetech Technologies
Gurugram
ABOUT THE ROLE
We are hiring experienced SOC Analysts who can work beyond conventional alert monitoring and contribute actively to threat hunting,
incident investigation, detection engineering, and proactive cybersecurity operations.
The role requires strong analytical capabilities,hands-on investigative skills, and a working knowledge of real-world attack methodologies.
The candidate must have mandatory hands-on experience with Elastic / ELK SIEM as the primary SIEM platform, while also being
comfortable working on other SIEM platforms depending on client environments.
The candidate should be capable of working across
the complete detection lifecycle from log ingestion, parsing, normalization, rule creation, alert tuning, investigation, and reporting.
You will operate in dynamic and critical security environments including enterprise and government ecosystems where proactive
monitoring, deep telemetry analysis, and high-quality detections are essential to client outcomes.
KEY RESPONSIBILITIES
Perform proactive threat hunting across enterprise environments to identify advanced threats, lateral movement, and suspicious
behaviour.
Investigate security incidents end-to-end, analyse attack patterns, and conduct detailed root cause analysis.
Monitor and analyse logs, alerts, and telemetry from SIEM, EDR, firewall, and network security platforms.
Work hands-on with Elastic / ELK SIEM as the primary platform for log onboarding, ingestion pipeline validation, parsing, field
mapping, alert creation, and investigation workflows, while adapting to other SIEM platforms as required by client environments.
Create, test, tune, and maintain custom detection rules, correlation logic, dashboards, and alerts in Elastic SIEM and other
client-specific SIEM platforms based on real-world attack techniques and operational requirements.
Understand and manage the complete SIEM detection pipeline from data source integration and log parsing to detection logic,
alert generation, triage, and escalation.
Develop and optimise SIEM detection use cases, correlation rules, and detection logic mapped to the MITRE ATT&CK; framework.
Conduct adversary simulation exercises and support purple teaming activities in partnership with the offensive security team.
n Perform malware analysis, IOC correlation, and threat intelligence-driven investigations.
SVELTETECH TECHNOLOGIES SOC Analyst Threat Hunting & Incident Investigation •
Prepare incident reports, technical findings, and explicit mitigation recommendations for both technical and executive audiences.
Coordinate with internal teams and clients during active security incidents and investigations.
Continuously improve monitoring strategies, detection coverage, and SOC playbooks based on emerging threats and lessons
learned
.
REQUIRED SKILLS & EXPERIENCE
7 years of experience in SOC operations, threat hunting, incident response, or cybersecurity operations.
Strong understanding of attack techniques, threat actor methodologies, and the MITRE ATT&CK; framework.
Mandatory hands-on experience with Elastic / ELK SIEM as the primary SIEM platform, including log ingestion, parsing, index/data
stream understanding, custom detection rule creation, alert tuning, dashboards, and investigation workflows.
Experience working with other SIEM platforms such as Splunk, QRadar,
Microsoft Sentinel, Wazuh, or equivalent will be required
depending on client-specific environments and project requirements.
Strong understanding of how logs move from source systems into SIEM including Beats/Agents, Logstash/Ingest Pipelines, field
extraction, normalization, correlation, and alert generation.
Demonstrated experience in log analysis, threat investigation, and security event correlation across diverse data sources.
Working knowledge of Windows, Linux, Active Directory, networking, and cloud security concepts.
Experience with threat intelligence platforms and IOC enrichment / analysis.
Strong analytical, investigative, and problem-solving skills — able to pivot quickly across data sets during an investigation.
PREFERRED QUALIFICATIONS
Prior experience in government, telecom, enterprise SOC, or critical infrastructure environments.
Relevant certifications such as CEH, CHFI, GCIA, GCIH, GCFA, Splunk, Elastic, Microsoft Sentinel, QRadar, or equivalent.
Elastic Security / Elastic SIEM certification or proven project experience in building Elastic-based SOC use cases will be strongly
preferred.
Exposure to scripting and automation (Python, PowerShell, KQL, SPL) for security operations and SOAR workflows.
Familiarity with detection-as-code practices and authoring Sigma, YARA, or Suricata rules.
Contributions to the security community — detection rules, threat research write-ups, blog posts, or open-source security tooling.
WORK LOCATION
Onsite role based out of the Sveltetech Gurugram office (Sector 61, Golf Course Extension Road) or client locations, depending on
project requirements. Given the operational nature of SOC work, shift-based or extended-hours coverage may be required for specific
engagements.
📌 Soc Analyst (Gurugram)
🏢 Sveltetech Technologies
📍 Gurugram