24 Aug
|
Businessnext
|
Noida
24 Aug
Businessnext
Noida
What would you do?
- Design, develop, and optimize high-fidelity detection rules across SIEM, EDR/XDR, cloud, identity, email, and network security platforms.
- Assess telemetry coverage across endpoint, network, identity, cloud, and SaaS environments, identifying visibility gaps and recommending improvements.
- Translate threat intelligence, threat hunting findings, and incident learnings into actionable detections and use cases.
- Continuously improve detection fidelity by reducing false positives, eliminating duplicate alerts, and expanding detection coverage.
- Lead technical investigations for complex and high-severity security incidents, providing guidance on containment, eradication, and recovery.
- Develop and maintain automation and orchestration workflows using SOAR platforms to improve SOC efficiency.
- Support cloud security monitoring across AWS, Azure, and GCP environments.
- Evaluate and improve security visibility for containers, Kubernetes, and modern application environments.
- Create and maintain technical documentation, detection logic, runbooks, and operational procedures.
- Stay current with emerging cyber threats, attack techniques, and advancements in security technologies.
AI Enabled Qualifications
- Demonstrated ability to leverage AI-powered tools for IT operations, incident analysis, workflow automation, and operational reporting.
- Proactive in adopting emerging AI technologies to enhance system reliability, team productivity, and data-driven decision-making.
Qualifications &
Requirements • 5+ years of experience in Security Operations, SOC Engineering, Detection Engineering, or Incident Response.
- Hands-on experience administering enterprise SIEM platforms such as Microsoft Sentinel, Splunk Enterprise Security, Elastic, IBM QRadar.
- Strong understanding of SIEM architecture, log management, parsing, normalization, correlation rules, data models, and performance optimization.
- Strong knowledge of MITRE ATT&CK;, cyber kill chain, threat detection methodologies, and attacker tactics and techniques.
- Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike Falcon, SentinelOne, or Cortex XDR.
- Working knowledge of cloud security services across AWS, Azure, or Google Cloud Platform. Strong understanding of Windows, Linux, Active Directory, Entra ID, networking protocols, and authentication technologies.
- Experience with scripting or automation using Python, PowerShell, or Bash.
- Experience working with SOAR platforms and security automation.
- Solid analytical, troubleshooting, and problem-solving skills.
- Excellent communication skills with the ability to collaborate across technical and business teams.
📌 Soc Analyst (Noida)
🏢 Businessnext
📍 Noida