Job Description - SOC Analyst (Incident Response & Threat Operations)
Position Summary
The SOC Analyst is responsible for end-to-end investigation, response, and management
of cybersecurity incidents across the enterprise. This role combines deep technical
incident handling, threat analysis, and proactive threat hunting with operational
leadership, cross-functional coordination, and continuous improvement of SOC
capabilities. The analyst plays a critical role in protecting the organization’s global
workplace by identifying threats, containing incidents, and strengthening the overall
security posture.
Key Responsibilities
Incident Investigation & Response
- Perform in-depth investigation of security incidents involving endpoints, servers,
- Assess risk, scope, root cause, and business impact of security events and
confirmed incidents
- Lead containment, eradication, and recovery actions for malware infections,
phishing attacks, ransomware activity, data exposure events, and malicious network
communications
- Act as a technical escalation point during high-severity and complex cyber
incidents, providing expert guidance and decision-making
- Manage the full incident lifecycle using XSOAR platforms, ensuring incidents are
handled e?iciently from detection through closure
Threat Analysis & Hunting
- Conduct proactive threat hunting to identify stealthy threats, anomalous behavior,
and attacker techniques not detected by automated controls
- Perform daily threat analysis activities including:
o New, aged, and dropped domain analysis
o Malicious IP, URL, and file hash validation
- Leverage internal telemetry and external threat intelligence sources to enrich
investigations and improve detection accuracy
Security Monitoring & Tooling
Security, Database Security, and Cloud Security platforms
- Support and enhance detection logic, correlation rules, and automated response
playbooks within SIEM and XSOAR platforms
- Partner with security engineering and
📌 Assistant Manager (Noida)
🏢 MetLife
📍 Noida