Job Description
Cyber Security Analyst (SOC)
n
Location: Pune
n
Experience: 2+ years
n
Immediate Joiners Preferred.
n
n
For Immediate response, Kindly share resumes to
[email protected] with Sub of "Cyber Security Analyst" along with Notice period.
n
n
Role Summary
n
We are seeking a Cyber Security Analyst with 2+ years of hands-on SOC experience to monitor, detect, investigate, and respond to cyber security threats across the enterprise environment. The ideal candidate will have strong knowledge of cyber-attack techniques, threat hunting, incident response, vulnerability management, and security operations processes.
n
This role will leverage a modern security technology stack centered around Microsoft Sentinel, Microsoft Defender, Microsoft Entra ID (Azure AD), Tenable, and Email Security platforms such as Proofpoint, Abnormal Security, or equivalent solutions . The successful candidate will be responsible for proactive threat detection, incident investigation, security monitoring, and continuous improvement of security operations capabilities.
n
n
Core Responsibilities
n
n
- Monitor security events, alerts, and incidents through SIEM, XDR/EDR and email security platforms.
n
- Investigate and respond to security alerts, suspicious activities, malware infections, phishing attempts, account compromises, and other cyber threats.
n
- Perform proactive threat hunting activities using available telemetry, threat intelligence, and behavioral indicators.
n
- Analyze attacker tactics, techniques, and procedures (TTPs) using the MITRE ATT&CK; framework.
n
- Create threat hunting hypotheses and identify potential indicators of compromise (IOCs) within the environment.
n
- Validate, tune, and optimize detection rules, analytics, alerting logic, and security playbooks to reduce false positives and improve detection capabilities.
n
- Investigate high-severity incidents and coordinate response activities with IT and business stakeholders.
n
- Support incident containment, eradication, recovery,
and post-incident analysis activities.
n
- Monitor and manage vulnerabilities identified through Tenable and Microsoft security solutions, working with infrastructure teams to ensure timely remediation.
n
- Perform root cause analysis of security incidents and provide actionable recommendations.
n
- Conduct phishing investigations and email threat analysis using enterprise email security solutions.
n
- Develop and maintain incident response procedures, investigation runbooks, and operational documentation.
n
- Participate in tabletop exercises, purple team activities, and cyber security incident simulations.
n
- Generate operational security reports, dashboards, and metrics for technical and non-technical stakeholders.
n
- Maintain awareness of emerging cyber threats, vulnerabilities, attack campaigns, and adversary techniques.
n
- Ensure all security incidents and investigations are properly documented and tracked through completion.
n
- Collaborate closely with SOC, IT Operations, Infrastructure, Cloud, and End User Computing teams to enhance overall security posture.
n
n
n
Required Technical Skills
n
Security Operations (SOC)
n
n
- Robust understanding of SOC operations, incident response, threat detection, and cyber attack methodologies.
n
- Experience investigating phishing, malware, ransomware, business email compromise (BEC), credential theft, and insider threat incidents.
n
- Knowledge of MITRE ATT&CK; framework, Indicators of Compromise (IoCs), and threat intelligence.
n
n
SIEM
n
n
- Microsoft Sentinel
n
- Strong understanding of SIEM architecture, log analysis, correlation rules, and security monitoring.
n
n
XDR / EDR
n
n
- Microsoft Defender XDR
n
- Microsoft Defender for Endpoint
n
- Experience investigating endpoint, identity, cloud, and email-related security incidents.
n
n
Identity Security
n
n
- Microsoft Entra ID (Azure AD)
n
- Conditional Access Policies
n
- Identity Protection
n
- Authentication and access-related security monitoring
n
n
Email Security
n
n
- Proofpoint, Abnormal Security, Microsoft Defender for Office 365, or equivalent email security platforms
n
- Phishing analysis and email threat investigations
n
n
Vulnerability Management
n
n
- Tenable.io / Tenable.sc / Nessus
n
- Vulnerability assessment, prioritization, remediation tracking, and reporting
n
n
Threat Hunting
n
n
- Threat hunting methodologies
n
- Log and telemetry analysis
n
- Detection engineering and use case development
n
n
n
Preferred Qualifications
n
n
- Bachelor's degree in Cyber Security, Information Security, Computer Science, or related field.
n
- Experience working within a Security Operations Center (SOC) environment.
n
- Industry certifications such as:
n
- SC-200 (Microsoft Security Operations Analyst)
n
- Security+
n
- CEH
n
- CySA+
n
- GSEC
n
- AZ-500
n
- Experience with KQL (Kusto Query Language) for Microsoft Sentinel and Defender investigations.
n
- Strong analytical, investigative, and problem-solving skills.
n
- Ability to work independently and effectively manage multiple security investigations simultaneously.
n
n
n
Experience Required
n
n
- Minimum 2+ years of experience in Cyber Security Operations (SOC).
n
- Hands-on experience with:
n
- Microsoft Sentinel
n
- Microsoft Defender XDR
n
- Microsoft Defender for Endpoint
n
- Microsoft Entra ID (Azure AD)
n
- Tenable/Nessus
n
- Email Security platforms (Proofpoint, Abnormal Security, Defender for Office 365, or equivalent)
n
- Demonstrated experience in threat hunting, incident response, alert triage, and cyber attack investigations.
n
n
📌 Cyber Security Analyst (SOC) (Pune)
🏢 Genpact
📍 Pune