Job Summary
Experience 5-9 years in Security Operations, Incident Response, Threat Hunting, or Cyber Defense. Shift 24/7 Rotational (including weekends and public holidays).
Role Overview: We are seeking an experienced Incident Response Analyst with strong hands-on knowledge of SIEM investigations, EDR triage, advanced email security analysis, incident response, threat hunting, and security log analysis. The candidate will be responsible for investigating security incidents, coordinating with internal security teams, supporting remediation activities, and communicating findings to clients and stakeholders.
Responsibilities
- Monitor, triage, and investigate security s and incidents.
- Perform detailed incident analysis across endpoints, identity, email, cloud, and network environments.
- Correlate security events across multiple tools and data sources.
- Determine incident scope, severity, impact, and root cause.
- Support containment, remediation, recovery, and incident closure activities.
- Conduct proactive threat hunting and identify suspicious activity.
- Coordinate with SecOps, IAM, Cloud, Network, Infrastructure, and other technical teams.
- Maintain accurate investigation notes, incident timelines, and reports.
- Recommend improvements to security detections, response playbooks, and operational processes.
- Communicate investigation findings and recommendations to clients and stakeholders.
- Ensure proper handover of open incidents across shifts.
Mandatory Skills
- SIEM Platform - Splunk - Microsoft Sentinel - Cortex XSIAM is most prioritized
Requirements
- Writing and modifying SPL / KQL / XQL queries
- Investigating s and incidents
- Correlating events across multiple log sources
- Analyzing endpoint, identity, cloud, network, and authentication logs
- Identifying true positives, false positives, and suspicious activity
EDR Platform
- Microsoft Defender for Endpoint
- CrowdStrike Falcon
- Cortex XDR is most prioritized
Preferred Technologies
- Cortex XSIAM
- Cortex XDR
- Proofpoint Email Security
- Proofpoint TAP
- Proofpoint TRAP
- Microsoft Defender XDR
Core Technical Skills
- Mandatory Strong hands-on experience in security incident triage, investigation, containment, remediation, recovery, and closure.
- Advanced endpoint investigation skills, including process-tree, command-line, file, hash, registry, persistence, network-connection, and EDR telemetry analysis.
- Advanced email security investigation experience covering phishing, Business Email Compromise, email headers, sender infrastructure, malicious URLs, attachments.
- Ability to independently investigate malware, account compromise, endpoint compromise, identity attacks, cloud security incidents, and potential data exfiltration.
- Strong log analysis and event-correlation skills across endpoint, identity, email, cloud, authentication, network, DNS, proxy, VPN, and firewall telemetry.
- Hands-on threat hunting experience, including hypothesis-driven hunts, attacker-behavior analysis, and MITRE ATT&CK; mapping.
- Strong experience coordinating incident response and remediation activities with SecOps, IAM, Cloud, Network, Infrastructure, and other technical teams.
Soft Skills
- Strong written and verbal communication skills
- Good client-facing and stakeholder-management skills
- Ability to explain technical findings clearly
- Strong analytical and problem-solving capability
- Ability to manage multiple incidents and priorities
- Strong documentation and report-writing skills
- Ability to work independently and take ownership
- Effective collaboration with cross-functional teams
- Ability to work under pressure during critical incidents
- Robust shift-handover and incident-communication skills
Certifications
- GCIH
- GCFA
- SC-200
- CySA+
- ECIH
- or equivalent
Disclaimer: This job description has been sourced from a public domain and may have been modified by Naukri.com to improve clarity for our users. We encourage job seekers to verify all details directly with the employer via their official channels before applying.
📌 SOC Analyst (Noida)
🏢 UST
📍 Noida