Noida, Uttar PradeshLucknow, Uttar Pradesh
Job Summary
Job Description : Investigation Skills – Mandatory\\r\\nThe candidate must demonstrate strong investigation skills and should be able to: \\r\\n• Understand why an alert triggered and validate whether it is a true positive or false positive.\\r\\n• Build a complete incident timeline using logs from Sentinel, MDE, Defender XDR, identity, email, and network sources.\\r\\n• Identify initial access, execution, persistence, privilege escalation, lateral movement, command and control, and exfiltration indicators.\\r\\n• Analyze process trees, command-line arguments, parent-child process relationships, file hashes, network connections, login patterns, and endpoint behavior.\\r\\n• Correlate multiple low-level alerts into a meaningful incident narrative.\\r\\n• Determine the root cause, scope of compromise, impacted assets, and business risk.\\r\\n• Recommend containment, eradication, and remediation actions based on technical evidence.\\r\\n• Document findings clearly for SOC leadership, technical teams, and customer stakeholders.\\r\\n
Job Summary : • Monitor, triage, investigate, and respond to security alerts using Microsoft Sentinel. • Handle escalated incidents from L1 analysts and perform detailed technical investigation. • Investigate incidents across Microsoft Defender for Endpoint, Microsoft Defender XDR, Microsoft Sentinel, Azure AD / Entra ID, email security, endpoint telemetry, and cloud logs. • Perform advanced analysis of endpoint alerts including malware execution, suspicious process activity, command-line behavior, persistence mechanisms, lateral movement, credential access, and defense evasion techniques. • Analyze Defender XDR incidents by correlating endpoint, identity, email, SaaS, and cloud signals. • Use KQL queries in Sentinel and Advanced Hunting to identify suspicious activity, validate alerts, perform threat hunting, and support incident scoping. • Determine incident severity, root cause, impacted users/devices, attack vector, timeline of events, and containment requirements. • Investigate common and advanced security incidents including phishing, malware, ransomware, credential theft, business email compromise, brute force, impossible travel, suspicious sign-ins, privilege escalation, data exfiltration, and insider threat scenarios. • Map observed attacker behavior to the MITRE ATT&CK; framework. • Conduct log analysis across endpoints, identity platforms, firewalls, proxy, DNS, VPN, servers, cloud workloads, and applications. • Perform threat hunting based on indicators of compromise, tactics, techniques, procedures, and emerging threat intelligence. • Support incident containment and remediation activities, including device isolation, account disablement, password reset, malicious email purge, IOC blocking, and endpoint remediation coordination. • Fine-tune detection rules, Sentinel analytics rules, automation rules, watchlists, and incident handling processes. • Work with SOAR playbooks and automation workflows to improve response efficiency and reduce manual effort. • Create clear and detailed incident reports covering investigation summary, technical evidence, root cause, impact,
containment actions, remediation steps, and recommendations. • Mentor L1 analysts on alert triage, investigation methodology, escalation quality, and documentation standards. • Ensure adherence to SOC SLAs, escalation procedures, quality standards, and operational governance requirements.
Key Responsibilities
Job Responsibilities : • Monitor, triage, investigate, and respond to security alerts using Microsoft Sentinel. • Handle escalated incidents from L1 analysts and perform detailed technical investigation. • Investigate incidents across Microsoft Defender for Endpoint, Microsoft Defender XDR, Microsoft Sentinel, Azure AD / Entra ID, email security, endpoint telemetry, and cloud logs. • Perform advanced analysis of endpoint alerts including malware execution, suspicious process activity, command-line behavior, persistence mechanisms, lateral movement, credential access, and defense evasion techniques. • Analyze Defender XDR incidents by correlating endpoint, identity, email, SaaS, and cloud signals. • Use KQL queries in Sentinel and Advanced Hunting to identify suspicious activity, validate alerts, perform threat hunting, and support incident scoping. • Determine incident severity, root cause, impacted users/devices, attack vector, timeline of events, and containment requirements. • Investigate common and advanced security incidents including phishing, malware, ransomware, credential theft, business email compromise, brute force, impossible travel, suspicious sign-ins, privilege escalation, data exfiltration, and insider threat scenarios. • Map observed attacker behavior to the MITRE ATT&CK; framework. • Conduct log analysis across endpoints, identity platforms, firewalls, proxy, DNS, VPN, servers, cloud workloads, and applications. • Perform threat hunting based on indicators of compromise, tactics, techniques, procedures, and emerging threat intelligence. • Support incident containment and remediation activities, including device isolation, account disablement, password reset, malicious email purge, IOC blocking, and endpoint remediation coordination. • Fine-tune detection rules, Sentinel analytics rules, automation rules, watchlists, and incident handling processes. • Work with SOAR playbooks and automation workflows to improve response efficiency and reduce manual effort. • Create clear and detailed incident reports covering investigation summary, technical evidence, root cause, impact, containment actions, remediation steps, and recommendations. • Mentor L1 analysts on alert triage, investigation methodology, escalation quality, and documentation standards. • Ensure adherence to SOC SLAs, escalation procedures, quality standards, and operational governance requirements.
Skill Requirements
Skill Requirement :
• Robust hands-on experience with Microsoft Sentinel as a SIEM platform. • Strong working knowledge of Microsoft Defender for Endpoint. • Strong understanding of Microsoft Defender XDR incident correlation across endpoint, identity, email, and cloud signals. • Good experience in KQL for Sentinel investigation, log correlation, and Advanced Hunting. • Ability to investigate complex security incidents beyond basic alert review. • Strong understanding of Windows endpoint internals including processes, registry, services, scheduled tasks, PowerShell, WMI, command-line activity, persistence techniques, and malware behavior. • Good understanding of endpoint attack techniques such as credential dumping, suspicious PowerShell, encoded commands, lateral movement, privilege escalation, persistence, and defense evasion. • Ability to analyze authentication logs, risky sign-ins, MFA failures, impossible travel, conditional access events, and suspicious user activity. • Understanding of email security investigations including phishing, malicious attachments, suspicious URLs, spoofing, impersonation, and mailbox compromise. • Familiarity with Microsoft Entra ID, Azure activity logs, Microsoft 365 security logs, and cloud security signals. • Strong log analysis skills across endpoint, identity, network, firewall, proxy, DNS, VPN, and cloud sources. • Understanding of incident response lifecycle including preparation, detection, analysis, containment, eradication, recovery, and lessons learned. • Good knowledge of MITRE ATT&CK; framework and ability to map alerts and incidents to attack techniques. • Experience in detection tuning, false positive reduction, alert enrichment, and use case improvement. • Basic scripting or automation knowledge using PowerShell, Python, or Logic Apps is preferred. • Understanding of SOC operations, escalation management, severity classification, and incident documentation standards.
Other Requirements
Other Requirement : Investigation Skills – Mandatory The candidate must demonstrate strong investigation skills and should be able to: • Understand why an alert triggered and validate whether it is a true positive or false positive. • Build a complete incident timeline using logs from Sentinel, MDE, Defender XDR, identity, email, and network sources. • Identify initial access, execution, persistence, privilege escalation, lateral movement, command and control, and exfiltration indicators. • Analyze process trees, command-line arguments, parent-child process relationships, file hashes, network connections, login patterns, and endpoint behavior. • Correlate multiple low-level alerts into a meaningful incident narrative. • Determine the root cause, scope of compromise, impacted assets, and business risk. • Recommend containment, eradication, and remediation actions based on technical evidence. • Document findings clearly for SOC leadership, technical teams, and customer stakeholders.
#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-
📌 SeniorAdministrator - Security Analysis, SIEM (India)
🏢 HCLTech
📍 India