27 Aug
|
nTech Workforce
|
India
27 Aug
nTech Workforce
India
Role : SOC Analyst
No. of Positions : 1
Contract Duration : 6 Months-12 Months
Location : Hyderabad
Mode of Work : Onsite
Shift Timings : Afternoon Shift
:
Role is 100% in Hyderabad office.
Overview :
The Senior SOC Analyst serves as the highest-level escalation point within the Security Operations Centre, specializing in complex investigations, advanced detection engineering support, and end-to-end incident response leadership. This role requires a high degree of technical depth, cross-functional collaboration, and the ability to guide SOC improvements through automation, AI-assisted workflows, and mentorship of junior analysts. Senior analysts shape SOC maturity through expert-level case handling, content refinement, proactive threat hunting support, and ongoing leadership in improving SOC processes, tooling, and response efficiency.
Key Responsibilities :
Advanced Investigation, Incident Handling &
- Incident Response :
- Lead complex, high-severity investigations across endpoint, network, cloud, and identity telemetry.
- Perform root cause analysis and reconstruct incident timelines using aligned MITRE ATT&CK; mapping.
- Serve as the primary technical liaison during escalated incidents, delivering clear findings and remediation steps to internal leadership and clients.
- Drive the creation of After-Action Reports (AARs) and lessons learned to improve tooling, detections, and workflow performance.
Detection Engineering &
- Content Support :
- Identify detection gaps and collaborate with Detection Engineering to develop, refine, and tune SIEM and EDR rules.
- Validate new detections before SOC deployment and provide measurable feedback based on production telemetry.
SOAR Automation &
- Workflow Optimization :
- Leverage SOAR platforms to automate enrichment, triage, and response actions.
- Identify repetitive patterns ideal for automation and propose workflow enhancements to reduce MTTR.
- Validate automation logic prior to production rollout and ensure alignment with SOC escalation policies.
- Collaborate with engineering teams to incorporate additional enrichment sources, threat intel lookups, and AI-driven analysis steps.
AI, Machine Learning &
- Prompt Engineering :
- Utilize AI copilots, enrichment agents, and LLM-based analysis tools to support case triage, enrichment, and investigation.
- Develop, optimize, and maintain prompt templates for SOC use cases (enrichment summaries, detection validation, log interpretation, hypothesis generation).
- Evaluate the accuracy and reliability of AI-generated outputs and implement QA steps to avoid hallucinations or misleading results.
- Identify opportunities to integrate AI agents into detection, triage, and response workflowsimproving analyst speed and consistency.
- Provide feedback to engineering teams on model behavior, content gaps, and automation integration opportunities.
Threat Hunting &
- Proactive Analysis :
- Support hypothesis-driven and intelligence-led hunts by validating findings, artifacts, and suspicious patterns.
- Recommend new hunts based on emerging TTPs, anomalous case trends, or telemetry gaps discovered during investigations.
- Ensure hunt findings translate into new detections, enhanced content, or instrumentation improvements.
Leadership, Mentoring &
- Team Development :
- Mentor junior analysts on investigation techniques, tooling proficiency,
case documentation, and proper analytical depth.
- Conduct quality reviews of Tier 1/2 case handling and provide constructive feedback.
- Contribute to training guides, runbooks, knowledge bases, and onboarding materials.
- Lead technical briefings, internal workshops, and knowledge-sharing sessions across SOC teams.
Reporting &
- Continuous Improvement :
- Produce clear, concise, and accurate technical reports, incident summaries, and executive-friendly communications.
- Identify inefficiencies and propose enhancements in monitoring, detection logic, processes, and analyst training.
Required Qualifications :
- 4-6 years of experience in cybersecurity, especially in SOC, threat hunting, detection engineering, or incident response roles.
- Robust understanding of threat hunting concepts and methodologies.
- Familiarity with EDR tools, SIEM platforms, and log analysis.
- Basic proficiency in writing detection queries or scripts (e.g., KQL, Sigma, PowerShell).
- Strong analytical thinking and investigative skills.
Preferred Qualifications :
- Certifications such as GCIH, GCFA, GCDA, or similar.
- Experience with Elastic, Splunk, or other search-based platforms.
- Knowledge of the MITRE ATT&CK; framework.
- Exposure to scripting languages for automation and enrichment.
Key Attributes :
- Curious and detail-oriented with a passion for proactive defence.
- Able to work independently or collaboratively in high-paced environments.
- Strong written and verbal communication skills.
- Bachelors degree in Cybersecurity, Information Technology, Computer Science, or a related field.
This role provides a hands-on opportunity to engage in proactive threat detection and response activities and contribute directly to the maturity and effectiveness of the SOCs security posture.
📌 Ntechworkforce - Senior Security Operations Center Analyst (India)
🏢 nTech Workforce
📍 India