31 Aug
|
Businessnext
|
Noida
31 Aug
Businessnext
Noida
What would you do?
• Design, develop, and optimize high-fidelity detection rules across SIEM, EDR/XDR, cloud, identity, email, and network security platforms. • Assess telemetry coverage across endpoint, network, identity, cloud, and SaaS environments, identifying visibility gaps and recommending improvements. • Translate threat intelligence, threat hunting findings, and incident learnings into actionable detections and use cases. • Continuously improve detection fidelity by reducing false positives, eliminating duplicate alerts, and expanding detection coverage. • Lead technical investigations for complex and high-severity security incidents, providing guidance on containment, eradication, and recovery. • Develop and maintain automation and orchestration workflows using SOAR platforms to improve SOC efficiency. • Support cloud security monitoring across AWS, Azure, and GCP environments. • Evaluate and improve security visibility for containers, Kubernetes, and modern application environments. • Create and maintain technical documentation, detection logic, runbooks, and operational procedures. • Stay current with emerging cyber threats, attack techniques, and advancements in security technologies. AI Enabled Qualifications: • Demonstrated ability to leverage AI-powered tools for IT operations, incident analysis, workflow automation, and operational reporting.
• Proactive in adopting emerging AI technologies to enhance system reliability, team productivity, and data-driven decision-making. Qualifications & Requirements • 5+ years of experience in Security Operations, SOC Engineering, Detection Engineering, or Incident Response. • Hands-on experience administering enterprise SIEM platforms such as Microsoft Sentinel, Splunk Enterprise Security, Elastic, IBM QRadar. • Strong understanding of SIEM architecture, log management, parsing, normalization, correlation rules, data models, and performance optimization. • Robust knowledge of MITRE ATT&CK;, cyber kill chain, threat detection methodologies, and attacker tactics and techniques. • Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike Falcon, SentinelOne, or Cortex XDR. • Working knowledge of cloud security services across AWS, Azure, or Google Cloud Platform. Strong understanding of Windows, Linux, Active Directory, Entra ID, networking protocols, and authentication technologies. • Experience with scripting or automation using Python, PowerShell, or Bash. • Experience working with SOAR platforms and security automation. • Strong analytical, troubleshooting, and problem-solving skills. • Excellent communication skills with the ability to collaborate across technical and business teams.
📌 Soc Analyst (Noida)
🏢 Businessnext
📍 Noida