Cyber Security Analyst (SOC)
Location: Pune
Experience: 2+ years
Immediate Joiners Preferred.
For Immediate response, Kindly share resumes to with Sub of "Cyber Security Analyst" along with Notice period.
Role Summary
We are seeking a Cyber Security Analyst with 2+ years of hands-on SOC experience to monitor, detect, investigate, and respond to cyber security threats across the enterprise environment. The ideal candidate will have strong knowledge of cyber-attack techniques, threat hunting, incident response, vulnerability management, and security operations processes.
This role will leverage a modern security technology stack centered around Microsoft Sentinel, Microsoft Defender, Microsoft Entra ID (Azure AD), Tenable, and Email Security platforms such as Proofpoint, Abnormal Security, or equivalent solutions . The successful candidate will be responsible for proactive threat detection, incident investigation, security monitoring, and continuous improvement of security operations capabilities.
Core Responsibilities
- Monitor security events, alerts, and incidents through SIEM, XDR/EDR and email security platforms.
- Investigate and respond to security alerts, suspicious activities, malware infections, phishing attempts, account compromises, and other cyber threats.
- Perform proactive threat hunting activities using available telemetry, threat intelligence, and behavioral indicators.
- Analyze attacker tactics, techniques, and procedures (TTPs) using the MITRE ATT&CK; framework.
- Create threat hunting hypotheses and identify potential indicators of compromise (IOCs) within the environment.
- Validate, tune, and optimize detection rules, analytics, alerting logic, and security playbooks to reduce false positives and improve detection capabilities.
- Investigate high-severity incidents and coordinate response activities with IT and business stakeholders.
- Support incident containment, eradication, recovery,
and post-incident analysis activities.
- Monitor and manage vulnerabilities identified through Tenable and Microsoft security solutions, working with infrastructure teams to ensure timely remediation.
- Perform root cause analysis of security incidents and provide actionable recommendations.
- Conduct phishing investigations and email threat analysis using enterprise email security solutions.
- Develop and maintain incident response procedures, investigation runbooks, and operational documentation.
- Participate in tabletop exercises, purple team activities, and cyber security incident simulations.
- Generate operational security reports, dashboards, and metrics for technical and non-technical stakeholders.
- Maintain awareness of emerging cyber threats, vulnerabilities, attack campaigns, and adversary techniques.
- Ensure all security incidents and investigations are properly documented and tracked through completion.
- Collaborate closely with SOC, IT Operations, Infrastructure, Cloud, and End User Computing teams to enhance overall security posture.
Required Technical Skills
Security Operations (SOC)
- Strong understanding of SOC operations, incident response, threat detection, and cyber attack methodologies.
- Experience investigating phishing, malware, ransomware, business email compromise (BEC), credential theft, and insider threat incidents.
- Knowledge of MITRE ATT&CK; framework, Indicators of Compromise (IoCs), and threat intelligence.
SIEM
- Microsoft Sentinel
- Strong understanding of SIEM architecture, log analysis, correlation rules,
and security monitoring.
XDR / EDR
- Microsoft Defender XDR
- Microsoft Defender for Endpoint
- Experience investigating endpoint, identity, cloud, and email-related security incidents.
Identity Security
- Microsoft Entra ID (Azure AD)
- Conditional Access Policies
- Identity Protection
- Authentication and access-related security monitoring
Email Security
- Proofpoint, Abnormal Security, Microsoft Defender for Office 365, or equivalent email security platforms
- Phishing analysis and email threat investigations
Vulnerability Management
- Tenable.io / Tenable.sc / Nessus
- Vulnerability assessment, prioritization, remediation tracking, and reporting
Threat Hunting
- Threat hunting methodologies
- Log and telemetry analysis
- Detection engineering and use case development
Preferred Qualifications
- Bachelor's degree in Cyber Security, Information Security, Computer Science, or related field.
- Experience working within a Security Operations Center (SOC) workplace.
- Industry certifications such as:
- SC-200 (Microsoft Security Operations Analyst)
- Security+
- CEH
- CySA+
- GSEC
- AZ-500
- Experience with KQL (Kusto Query Language) for Microsoft Sentinel and Defender investigations.
- Strong analytical, investigative, and problem-solving skills.
- Ability to work independently and effectively manage multiple security investigations simultaneously.
Experience Required
- Minimum 2+ years of experience in Cyber Security Operations (SOC).
- Hands-on experience with:
- Microsoft Sentinel
- Microsoft Defender XDR
- Microsoft Defender for Endpoint
- Microsoft Entra ID (Azure AD)
- Tenable/Nessus
- Email Security platforms (Proofpoint, Abnormal Security, Defender for Office 365, or equivalent)
- Demonstrated experience in threat hunting, incident response, alert triage, and cyber attack investigations.
📌 Cyber Security Analyst (SOC) (Pune)
🏢 Genpact
📍 Pune