Noida, Uttar Pradesh
Job Summary
Job Description : SOC Governance Experience – Mandatory\\r\\nThe candidate must have practical experience in SOC governance and operational oversight, including: \\r\\n• Reviewing SOC tickets and incidents for investigation quality, evidence completeness, severity accuracy, closure notes, and remediation tracking.\\r\\n• Tracking SLA performance, breach risks, escalation delays, aging incidents, repeat offenders, and operational gaps.\\r\\n• Driving governance calls, operational reviews, audit discussions, and service improvement actions with SOC leads, managers, and customer stakeholders.\\r\\n• Maintaining governance trackers, quality scorecards, incident review summaries, action item logs, and compliance evidence.\\r\\n• Identifying detection gaps, noisy use cases, false positive trends, automation opportunities, log source issues, and process deviations.\\r\\n• Supporting audit readiness by ensuring proper documentation, evidence retention, incident traceability, and adherence to agreed SOC operating procedures.\\r\\n
Job Summary : • Monitor, triage, investigate, and respond to security alerts using Microsoft Sentinel. • Handle escalated incidents from L1 analysts and perform detailed technical investigation. • Investigate incidents across Microsoft Defender for Endpoint, Microsoft Defender XDR, Microsoft Sentinel, Azure AD / Entra ID, email security, endpoint telemetry, and cloud logs. • Perform advanced analysis of endpoint alerts including malware execution, suspicious process activity, command-line behavior, persistence mechanisms, lateral movement, credential access, and defense evasion techniques. • Analyze Defender XDR incidents by correlating endpoint, identity, email, SaaS, and cloud signals. • Use KQL queries in Sentinel and Advanced Hunting to identify suspicious activity, validate alerts, perform threat hunting, and support incident scoping. • Determine incident severity, root cause,
📌 Track Lead (Noida)
🏢 HCLTech
📍 Noida