SOC Analyst (Bengaluru)

SOC Analyst (Bengaluru)

14 Aug
|
UST
|
Bengaluru

14 Aug

UST

Bengaluru

Role Description Incident Response Analyst Experience 5–9 years in Security Operations, Incident Response, Threat Hunting, or Cyber Defense Shift 24×7 Rotational (including weekends and public holidays) Role Overview We are seeking an experienced Incident Response Analyst with strong hands-on knowledge of SIEM investigations, EDR triage, advanced email security analysis, incident response, threat hunting, and security log analysis. The candidate will be responsible for investigating security incidents, coordinating with internal security teams, supporting remediation activities, and communicating findings to clients and stakeholders.

Key Responsibilities Monitor, triage, and investigate security s and incidents.

Perform detailed incident analysis across endpoints, identity, email, cloud, and network environments.

Correlate security events across multiple tools and data sources.

Determine incident scope, severity, impact, and root cause.

Support containment, remediation, recovery, and incident closure activities.

Conduct proactive threat hunting and identify suspicious activity.

Coordinate with SecOps, IAM, Cloud, Network, Infrastructure, and other technical teams.

Maintain accurate investigation notes, incident timelines, and reports.

Recommend improvements to security detections, response playbooks, and operational processes.

Communicate investigation findings and recommendations to clients and stakeholders.

Ensure proper handover of open incidents across shifts.

Mandatory

Skills SIEM Platform

Splunk

Microsoft Sentinel





Cortex XSIAM is most prioritized The candidate should have experience in:

Writing and modifying SPL / KQL / XQL queries

Investigating s and incidents

Correlating events across multiple log sources

Analyzing endpoint, identity, cloud, network, and authentication logs

Identifying true positives, false positives, and suspicious activity EDR Platform Strong hands-on experience with:

Microsoft Defender for Endpoint

CrowdStrike Falcon

Cortex XDR is most prioritized

Strong incident documentation and reporting skills Preferred Skills Experience with the following technologies is preferred:

Cortex XSIAM

Cortex XDR

Proofpoint Email Security

Proofpoint TAP

Proofpoint TRAP

Microsoft Defender XDR Core Technical Skills — Mandatory Robust hands-on experience in security incident triage, investigation, containment, remediation, recovery, and closure.

Advanced endpoint investigation skills, including process-tree, command-line, file, hash, registry, persistence, network-connection, and EDR telemetry analysis.

Advanced email security investigation experience covering phishing, Business Email Compromise, email headers, sender infrastructure, malicious URLs, attachments.





Ability to independently investigate malware, account compromise, endpoint compromise, identity attacks, cloud security incidents, and potential data exfiltration.

Strong log analysis and event-correlation skills across endpoint, identity, email, cloud, authentication, network, DNS, proxy, VPN, and firewall telemetry.

Hands-on threat hunting experience, including hypothesis-driven hunts, attacker-behavior analysis, and MITRE ATT&CK; mapping.

Strong experience coordinating incident response and remediation activities with SecOps, IAM, Cloud, Network, Infrastructure, and other technical teams. Soft Skills

Strong written and verbal communication skills

Good client-facing and stakeholder-management skills

Ability to explain technical findings clearly

Strong analytical and problem-solving capability

Ability to manage multiple incidents and priorities

Strong documentation and report-writing skills

Ability to work independently and take ownership

Effective collaboration with cross-functional teams

Ability to work under pressure during critical incidents

Strong shift-handover and incident-communication skills Certifications — Preferred Industry-recognized certifications in Security Operations, Incident Response, Digital Forensics, or Threat Hunting are preferred, such as GCIH, GCFA, SC-200, CySA+, ECIH, or equivalent. Relevant hands-on SOC and Incident Response experience will be given greater consideration than certifications alone.

Skills SIEM, Splunk, MITRE ATT&CK;, Log Analysis

📌 SOC Analyst (Bengaluru)
🏢 UST
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: soc analyst (bengaluru) / bengaluru