CYBER SECURITY ANALYST (Pune)

CYBER SECURITY ANALYST (Pune)

05 Sep
|
Wipro
|
Pune

05 Sep

Wipro

Pune

Job Title: CYBER SECURITY ANALYST L4
City: Pune
State/Province: Maharashtra
Posting Start Date: 9/1/26
Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO) is a leading technology services and consulting company focused on building innovative solutions that address clients’ most complex digital transformation needs. Leveraging our holistic portfolio of capabilities in consulting, design, engineering, and operations, we help clients realize their boldest ambitions and build future-ready, sustainable businesses. With over 230,000 employees and business partners across 65 countries, we deliver on the promise of helping our customers, colleagues, and communities thrive in an ever-changing world. For additional information, visit us at www.wipro.com.

Role Purpose

The purpose of this role is to analyze attack patterns, develop incident response plans, ensure audit readiness, and implement disaster recovery measures, to ensure adherence to cyber security regulatory frameworks.

͏

Areas of responsibility

Monitoring and Incident Detection-Analyse attack trends and correlate logs across systems to identify advance threats. Enhance monitoring processes and implement improvements for faster detection, to ensure compliance with security frameworks and regulatory standards.

Incident Handling and Analysis-Perform root cause analysis, create incident response plans and implement disaster recovery measures to minimize business disruption

Threat Assessment and Analytics-Undertake forensic analysis using advanced analytics tools and implement mitigation measures to align with compliance requirements.

Stakeholder Coordination and Audit Assistance-"Liaise with cross functional teams, external vendors and auditors to ensure compliance with security frameworks.

Maintain audit documentation and ensure its accuracy while implementing processes that support audit readiness and continuous compliance."

Training and Awareness-Assist in creating and delivering cybersecurity awareness sessions, including guidance on phishing and malicious emails.

͏
͏
͏

Cyber Defense / SOC Lead

Experience: 8–10 Years

Domain: Cyber Defense | SOC | SIEM | Threat Detection & Incident Response

Primary Technologies: Microsoft Sentinel, Microsoft Defender XDR, Defender for Endpoint, Defender for Office 365, Entra ID, Defender for Cloud Apps, Mimecast

Job Summary

Cyber Defense professional with 8–10 years of experience in Security Operations, SIEM monitoring, threat detection, incident response, threat hunting and security engineering. Responsible for operating and improving a 24x7 SOC setting, with strong hands-on experience across the Microsoft Security ecosystem, including Microsoft Sentinel, Microsoft Defender XDR, Defender for Endpoint, Defender for Office 365, Entra ID and Defender for Cloud Apps.

The role involves end-to-end investigation of security incidents, phishing and email security incidents, detection engineering, KQL-based threat hunting, SIEM content development, security monitoring, automation and continuous tuning of security controls.

Key Responsibilities

Security Operations & Incident Response

- Monitor and manage security incidents and alerts in Microsoft Sentinel and Microsoft Defender XDR.
- Perform end-to-end triage, investigation, containment, remediation and closure of security incidents.
- Investigate high-severity incidents involving compromised accounts, malware, ransomware, suspicious PowerShell activity, brute-force attacks, impossible travel, anomalous sign-ins and endpoint threats.
- Perform incident correlation across endpoint, identity, email, cloud and network security telemetry.
- Coordinate with IT, Infrastructure, Identity, Network,



Cloud and Application teams during security incidents.
- Prepare detailed incident reports, root-cause analysis, impact assessment and remediation recommendations.
- Support 24x7 SOC operations, shift handovers, escalations and incident response processes.

Phishing & Email Security

- Investigate phishing, malicious email, spoofing, business email compromise and credential-harvesting incidents.
- Analyze email headers, sender reputation, URLs, attachments, domains, IP addresses and other indicators of compromise.
- Perform email remediation and deletion using Mimecast / Microsoft Defender for Office 365.
- Identify malicious campaigns and hunt for similar messages across the organization.
- Coordinate with users and IT teams for compromised mailbox and credential-related incidents.
- Develop and maintain phishing investigation SOPs and response procedures.

Microsoft Sentinel / SIEM

- Develop, maintain and fine-tune Microsoft Sentinel Analytics Rules using KQL.
- Create advanced hunting queries for suspicious authentication, endpoint, cloud and network activity.
- Perform false-positive analysis and continuously optimize detection logic.
- Develop Sentinel Workbooks and dashboards for SOC KPIs, incident trends, severity, MITRE ATT&CK; techniques, MTTT and MTTR.
- Manage watchlists, threat intelligence indicators and custom detections.
- Work with multiple data sources including Entra ID, Azure Activity Logs, Defender, Mimecast, Cloud App Events, Azure services and network/security platforms.
- Troubleshoot data connector and log ingestion issues and validate data availability and quality.

Threat Hunting

- Conduct proactive threat hunting using Microsoft Sentinel, Defender XDR and advanced KQL queries.
- Hunt for known and emerging IOCs including malicious IPs, domains, URLs, hashes and suspicious processes.
- Investigate techniques such as credential dumping, password spraying, distributed brute-force attacks, PowerShell abuse, lateral movement and ransomware activity.
- Map detections and hunting activities to the MITRE ATT&CK; framework.
- Research emerging threats, malware campaigns, vulnerabilities and supply-chain attacks and translate findings into actionable detections.

Microsoft Defender / Endpoint Security

- Monitor and investigate endpoint alerts using Microsoft Defender for Endpoint.
- Perform endpoint investigation, device isolation/containment and remediation activities.
- Analyze process trees, command lines, network connections, file activity and user behavior.
- Use Defender Live Response for advanced endpoint investigation and evidence collection.
- Investigate inactive or unhealthy Defender sensors and coordinate remediation.
- Develop endpoint-focused hunting queries and detection strategies.

Identity & Cloud Security

- Investigate Entra ID sign-in and authentication-related incidents.
- Analyze suspicious sign-ins, failed authentication attempts, disabled-account activity, MFA-related events and anomalous user behavior.
- Investigate compromised identities and coordinate account containment and remediation.
- Monitor Azure Activity Logs, Azure resources and cloud application activity.
- Support security monitoring across Microsoft 365 and Azure environments.

Detection Engineering & Automation

- Design and implement security detections based on threat intelligence,



incident learnings and MITRE ATT&CK; techniques.
- Develop Sentinel Automation Rules and Logic App playbooks for incident enrichment, notification and response.
- Automate repetitive SOC activities such as IOC enrichment, alert notifications and incident handling.
- Integrate threat intelligence sources and security platforms into the SOC ecosystem.
- Continuously improve detection coverage and reduce alert noise through tuning and automation.

SOC Process & Leadership

- Act as a technical lead / SME for Cyber Defense and SOC operations.
- Guide junior SOC analysts during incident investigation and escalation.
- Review analyst investigations and ensure adherence to SOC processes and SLAs.
- Create and maintain SOPs, Knowledge Base articles, investigation playbooks and operational documentation.
- Conduct knowledge-transfer sessions for new technologies, threats and investigation techniques.
- Support SOC transition, onboarding and operational readiness activities.
- Track operational metrics including incident volumes, severity trends, MTTT, MTTR, SLA compliance and detection effectiveness.

Core Technical Skills

- SIEM: Microsoft Sentinel
- EDR/XDR: Microsoft Defender for Endpoint, Microsoft Defender XDR
- Email Security: Microsoft Defender for Office 365, Mimecast
- Identity: Microsoft Entra ID / Azure AD
- Cloud Security: Microsoft Defender for Cloud Apps, Microsoft Defender for Cloud, Azure Security
- Threat Hunting: KQL, Microsoft Defender Advanced Hunting
- Automation: Sentinel Automation Rules, Logic Apps, Azure Functions
- Threat Intelligence: IOC analysis, threat feeds, IP/domain/hash reputation, MITRE ATT&CK;
- Security Operations: Incident Response, Alert Triage, Threat Hunting, Detection Engineering, SOC Monitoring
- Cloud & Logging: Azure Activity Logs, Log Analytics, Azure Diagnostics, App Service Logs, Azure Front Door
- Network/Security Tools: Zscaler, Cloudflare and other security/network telemetry sources
- Endpoint Security: Microsoft Defender, McAfee Endpoint Security, Sophos

Key Competencies

- Incident Response & Investigation
- Phishing & Email Threat Analysis
- Threat Hunting
- Detection Engineering
- KQL Query Development
- SIEM Engineering
- EDR/XDR Investigation
- Identity Threat Detection
- Threat Intelligence
- Security Automation
- MITRE ATT&CK; Mapping
- SOC Process Improvement
- Technical Leadership
- Security Documentation & SOP Development

Preferred Certifications

- Microsoft SC-200 – Security Operations Analyst
- Microsoft SC-100 – Cybersecurity Architect
- Microsoft AZ-500 – Azure Security Technologies
- Certified Ethical Hacker (CEH)
- Other relevant SOC, SIEM, Cloud Security or Incident Response certifications

Ideal Candidate Profile

A hands-on Cyber Defense professional with 8–10 years of SOC/Security Operations experience, capable of independently handling complex security incidents while also contributing to detection engineering, threat hunting, automation and SOC process improvement. Strong practical expertise in the Microsoft Sentinel + Defender XDR ecosystem, with the ability to lead investigations, mentor analysts and continuously improve the organization's overall detection and response capability.

Mandatory Skills: Vulnerability Management .

Experience: 5-8 Years .

Reinvent your world. We are building a modern Wipro. We are an end-to-end digital transformation partner with the boldest ambitions. To realize them, we need people inspired by reinvention. Of yourself, your career, and your skills. We want to see the constant evolution of our business and our industry. It has always been in our DNA - as the world around us changes, so do we. Join a business powered by purpose and a place that empowers you to design your own reinvention.

📌 CYBER SECURITY ANALYST (Pune)
🏢 Wipro
📍 Pune

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: cyber security analyst (pune) / pune

Subscribe to this job alert:

Get the latest job offers by email for: cyber security analyst (pune) / pune