Noida, Uttar Pradesh
Job Summary
Job Summary : Department: Security Operations Center (SOC) Experience Level: 1–3 Years Employment Type: Full-time Position Overview We are seeking a detail-oriented and proactive SOC Analyst with 1–3 years of hands-on security operations experience to join our team. In this role, you will serve as a core defender of our digital assets, utilizing Palo Alto Networks Cortex XSIAM to monitor, triage, investigate, and respond to security threats across our network, endpoints, cloud, and identity infrastructure. The ideal candidate understands modern threat landscapes, possesses strong analytical skills, and leverages automation and telemetry to reduce mean time to detect (MTTD) and mean time
Key Responsibilities
Job Responsibilities : 1. Incident Triage & Response Monitor and analyze security alerts, events, and incidents within Palo Alto Cortex XSIAM across endpoint, network, cloud, and identity telemetry sources. Conduct initial alert triage to differentiate between true positives and false positives, escalating complex threats when necessary. Perform root cause analysis, risk assessment, and scope determination for verified security incidents. Execute containment, mitigation, and remediation actions (e.g., endpoint isolation, user credential resets, IP blocking). 2. XSIAM Operations & Analysis Query and correlate security data across diverse data sources using Cortex Query Language (XQL). Validate and maintain Cortex XDR agent health across enterprise endpoints. Interact with automated SOAR playbooks to accelerate incident resolution and streamline repetitive tasks. Leverage Attack Surface Management (ASM)
and Identity Threat Detection & Response (ITDR) modules within XSIAM to identify vulnerabilities and identity risks. 3. Threat Detection & Intelligence Map observed adversary behaviors and indicators of compromise (IOCs) to the MITRE ATT&CK; framework. Integrate threat intelligence feeds into detection workflows to proactively hunt for emerging cyber threats. Assist senior analysts in fine-tuning detection rules and playbook workflows to minimize noise and improve response fidelity. 4. Documentation & Collaboration Maintain detailed incident logs, ticket updates, and post-incident reports with actionable mitigation recommendations. Collaborate closely with IT Infrastructure, Cloud, Engineering, and DevOps teams during security incidents.
Skill Requirements
Skill Requirement : Core Experience & Certifications 1 to 3 years of experience working in a Security Operations Center (SOC) or Incident Response setting. Direct experience using Palo Alto Networks Cortex XSIAM or Cortex XDR. Relevant industry certifications (at least one preferred): Palo Alto Networks Certified XSIAM Analyst or PCDRA (Palo Alto Networks Certified Detection and Remediation Analyst) CompTIA Security+, CySA+, or GIAC (GSEC/GCIH) Technical & Security Focus Skills SIEM / XDR / SOAR: Understanding of log ingestion, correlation, alert grouping,
and playbook execution within XSIAM. Querying Languages: Hands-on ability to write and modify XQL (Cortex Query Language) or similar SIEM query languages (KQL, SPL). Networking & Protocols: Solid grasp of TCP/IP, DNS, HTTP/S, VPNs, firewalls, and proxy architecture. Operating Systems & Endpoints: Working knowledge of Windows (Registry, Event Logs), Linux, and macOS internal security mechanisms. Attack Frameworks: Strong understanding of the MITRE ATT&CK; framework, Cyber Kill Chain, and common vector entry tactics (phishing, drive-by downloads, credential stuffing). Identity & Cloud Security: Familiarity with Active Directory, Microsoft Entra ID (Azure AD), SSO, MFA, and general AWS/Azure security concepts. Scripting (Plus): Basic proficiency in Python or PowerShell for basic automation and log parsing.
Other Requirements
Other Requirement : Soft Skills Strong problem-solving and critical-thinking abilities under pressure. Excellent clear verbal and written technical reporting skills. Ability to work effectively in shift/rotational monitoring operational environments. Preferred / Nice-to-Have Skills Experience with Palo Alto Next-Generation Firewalls (NGFW) or Prisma Cloud integrations. Experience participating in basic threat hunting or tabletop incident response exercises. Exposure to forensic artifact collection (memory dumps, PCAP analysis).
#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-
📌 Sr Engineer (Support & Operations) (Noida)
🏢 HCLTech
📍 Noida