27 Aug
|
NTECH IT SOLUTIONS PRIVATE
|
India
27 Aug
NTECH IT SOLUTIONS PRIVATE
India
We are looking for an experienced Senior SOC Analyst – AI Security with 5+ years of experience in Security Operations, Incident Response, Threat Detection, and AI-driven security operations. The candidate will be responsible for monitoring and analyzing security events, investigating cyber threats, responding to incidents, and leveraging AI/ML and automation to improve SOC detection and response capabilities.
Roles & Responsibilities
- Monitor and analyze security alerts, logs, and events from SIEM, EDR/XDR, NDR, firewall, cloud, and identity security platforms.
- Perform L1/L2/L3 security monitoring and incident investigation based on experience and organizational requirements.
- Investigate suspicious activities, malware, phishing, ransomware, credential attacks, privilege escalation, lateral movement, and data exfiltration.
- Perform incident triage, containment, eradication, recovery, and root-cause analysis.
- Develop and tune detection rules, correlation rules, alerts, and use cases to reduce false positives and improve threat detection.
- Work with Microsoft Sentinel, Splunk, QRadar, Elastic SIEM, or similar SIEM platforms.
- Work with EDR/XDR solutions such as Microsoft Defender, CrowdStrike, SentinelOne, or similar technologies.
- Analyze security telemetry from AWS, Azure, and/or GCP environments.
- Use MITRE ATT&CK;, Cyber Kill Chain, IOC, TTP, and threat intelligence frameworks for threat investigation.
- Perform proactive threat hunting across endpoint, network, identity, cloud, and application environments.
- Leverage AI/ML technologies and GenAI tools to improve alert triage, threat hunting, incident investigation, and security analysis.
- Use AI-assisted tools to summarize security events, correlate alerts, identify attack patterns, and accelerate incident response.
- Develop or support AI-powered SOC automation and security workflows using SOAR, Python, APIs, and automation frameworks.
- Evaluate AI-generated security findings and validate them against available logs, telemetry, threat intelligence, and investigation evidence.
- Understand security risks associated with Generative AI, LLMs, AI agents, prompt injection, data leakage, model abuse, and unauthorized AI usage.
- Monitor and investigate potential AI/LLM-related security incidents, including prompt injection, sensitive data exposure, malicious inputs, and unauthorized model/API access.
- Integrate threat intelligence and AI capabilities into existing SIEM/SOAR/SOC workflows.
- Create and maintain playbooks, runbooks, detection logic, incident response procedures, and investigation documentation.
- Automate repetitive SOC activities using Python, PowerShell, REST APIs, SOAR platforms, or scripting.
- Participate in vulnerability management, security assessments, and remediation tracking.
- Collaborate with Cloud, Network, IAM, DevOps, Application Security, and Infrastructure teams during security investigations.
- Prepare incident reports, executive summaries, metrics, and security dashboards.
- Participate in 24x7 SOC operations, on-call rotations, and major incident response, where required.
Required Skills
- 5+ years of experience in SOC, Cybersecurity Operations, Incident Response, Threat Detection, or Security Engineering.
- Strong hands-on experience with at least one SIEM platform:
- Microsoft Sentinel
- Splunk
- IBM QRadar
- Elastic Security
- Google Chronicle
- Experience with EDR/XDR solutions such as Microsoft Defender, CrowdStrike, SentinelOne, or equivalent.
- Strong knowledge of:
- SIEM and SOC operations
- Incident Response
- Threat Hunting
- Malware and phishing analysis
- Network security
- IAM and authentication
- Endpoint security
- Cloud security
- Threat intelligence
- Strong understanding of MITRE ATT&CK;, IOC, TTPs, and Cyber Kill Chain.
- Experience writing and tuning SIEM correlation/detection rules and security use cases.
- Hands-on knowledge of Windows and Linux security.
- Working knowledge of TCP/IP, DNS, HTTP/HTTPS, VPN, firewalls, proxies, and network security concepts.
- Experience with Python, PowerShell, or Shell scripting for security automation.
- Experience with SOAR and security automation is preferred.
- Knowledge of AI/ML and Generative AI security concepts.
- Experience using AI-assisted security tools for alert analysis, investigation, threat hunting, or SOC automation.
- Solid analytical, troubleshooting, communication, and incident-management skills.
AI & GenAI Security Skills
- Understanding of LLM security and AI threat landscape.
- Knowledge of OWASP Top 10 for LLM Applications and common AI security risks.
- Understanding of prompt injection, jailbreaks, data poisoning, sensitive information disclosure, excessive agency, and insecure AI integrations.
- Experience using AI/GenAI tools for:
- Alert summarization
- Threat investigation
- Log analysis
- IOC enrichment
- Threat hunting
- Incident reporting
- Detection engineering
- Ability to validate and critically assess AI-generated security recommendations before implementing them.
Pay: ₹16,886.48 - ₹74,375.98 per month
Work Location: In person
📌 SOC Analyst (India)
🏢 NTECH IT SOLUTIONS PRIVATE
📍 India