Soc Engineer (Kochi)

Soc Engineer (Kochi)

07 Sep
|
VPS Lakeshore
|
Kochi

07 Sep

VPS Lakeshore

Kochi

SOC Engineer

Security Operations Centre Monitoring, Detection & Incident Response

POSITION PURPOSE

The SOC Engineer owns the day-to-day security monitoring and incident response capability of VPS Lakeshore Medical Centre. A hospital runs 24x7 on systems that hold patient data including HIS/EMR, PACS, LIS, pharmacy, billing, Active Directory, and a large estate of connected clinical devices. A security incident in this environment is a patient-safety and continuity-of-care issue and is of a critical nature. The role is responsible for implementing and running the hospital's security tooling (SIEM, EDR/XDR, SOAR), detecting and investigating threats across that estate, driving incidents to closure with the IT Operations and application teams, and continuously improving detection quality so that real threats surface early and noise does not. The SOC Engineer must combine strong hands-on technical depth with disciplined documentation and an evidence-led approach under pressure.

KEY RESPONSIBILITIES

- SOC Tool Implementation & Administration — Implement, configure, maintain, and optimise SOC tooling. This includes but is not limited to SIEM, EDR/XDR, SOAR, and other security monitoring solutions as decided upon with management.
- Log Management & Integration — Manage log collection and onboarding from network devices, firewalls, servers, endpoints, security devices, clinical and business applications, and cloud platforms into the SIEM; validate parsing, normalisation, time synchronisation, and log-source availability, and act on ingestion failures.
- Security Monitoring & Log Analysis — Monitor and analyse security logs, events, and alerts to identify suspicious activity, anomalies, threats, and potential security incidents; triage alerts by severity and business impact, and maintain a clean, documented handover at the end of each shift or on-call window.
- Use Case Engineering & Rule Tuning — Develop, maintain, and tune SIEM correlation rules, alerts, dashboards, and security use cases mapped to attacks; measure and reduce false positives; build detections for hospital-specific risks such as unauthorised access to patient records, privileged account misuse, and ransomware precursor behaviour.
- Incident Investigation & Response — Perform incident investigation, establish root cause and scope, preserve evidence, and coordinate with the relevant teams for containment, eradication, remediation, recovery, and closure; follow defined incident response playbooks and support post-incident reviews.
- Incident Ticket Management — Create, update, track, and close security incident tickets with proper documentation, evidence, categorisation, prioritisation, escalation,



and resolution notes, in line with agreed SLAs.
- Threat Intelligence & Threat Hunting — Consume threat intelligence feeds and advisories relevant to healthcare; perform IOC analysis and proactive threat hunting across endpoint, network, identity, and cloud telemetry to find activity that existing detections have missed.
- Vulnerability & Exposure Support — Work with external agencies to support vulnerability scanning, patch-compliance reporting, and remediation follow-up with IT Operations and application owners; track closure of critical and high findings on the hospital estate.
- Email, Endpoint & Identity Security — Monitor and respond to phishing reports, malware detections, account compromise, and anomalous authentication activity; support email security, endpoint protection, MFA, conditional access, and privileged access controls.
- Clinical & Biomedical Environment Security — Work with the biomedical, applications, and infrastructure teams to bring clinical systems and connected medical devices (IoMT) into monitoring scope, respecting clinical availability and vendor-support constraints.
- IT Infrastructure Coordination — Coordinate with IT Operations, network, server, application, and vendor teams for security incident investigation, containment, and resolution, and for changes that affect the security monitoring estate.
- Documentation, Playbooks & SOPs — Maintain SOC documentation like response playbooks, escalation matrices, log-source inventory, and use-case catalogue.
- Reporting & Metrics — Produce periodic security reports and metrics like alert and incident volumes, detection coverage, mean time to detect and respond, false-positive rate, open risks for the Head of IT and hospital management.

QUALIFICATIONS & EXPERIENCE

- Bachelor's degree in Computer Science, Information Technology, Cyber Security, Electronics, or a related field.
- 6+ years of hands-on information security experience, with at least 2 years in a Security Operations Centre performing monitoring, detection engineering, and incident response.
- Demonstrated hands-on experience administering and tuning a SIEM platform — onboarding log sources, writing correlation rules and queries, and building dashboards.




- Practical experience investigating and closing security incidents end to end, with clear written documentation and evidence handling.
- Good working knowledge of IT infrastructure — networking, firewalls, servers, applications, and cloud — and how each generates security-relevant telemetry.
- Strong analytical and troubleshooting ability: structured, evidence-led, and calm under pressure.
- Clear written and verbal communication in English; ability to explain security risk to non-technical clinical and administrative staff. Working knowledge of Malayalam is an advantage.
- Willingness to provide on-call cover and respond to security escalations outside normal working hours.

TECHNICAL SKILLS

- SIEM — Microsoft Sentinel, Splunk, IBM QRadar, or a similar enterprise platform; comfortable with the platform's query language (KQL, SPL, AQL, or equivalent).
- EDR / XDR — Microsoft Defender for Endpoint, CrowdStrike, Trend Micro, or a similar solution — deployment, policy configuration, detection triage, and response actions.
- SOAR & Automation — Exposure to SOAR platforms and playbook automation; scripting in PowerShell, Python, or Bash for enrichment and routine tasks.
- Networking — Strong understanding of TCP/IP, DNS, HTTP/HTTPS, VPN, firewalls, proxies, and network security concepts; ability to read packet captures and firewall logs.
- Platforms & Identity — Working knowledge of Windows and Linux server and endpoint administration, Active Directory / Entra ID, business applications, and cloud environments (Azure, AWS, or GCP).
- Threat Knowledge — Good understanding of common attack techniques and vulnerabilities, the MITRE ATT&CK; framework, IOC analysis, and threat detection methodology.
- Frameworks — Familiarity with NIST CSF or the NIST incident-handling lifecycle, ISO 27001 controls, and ITIL incident management practices.

PREFERRED QUALIFICATIONS

- Security certifications such as CompTIA Security+ or CySA+, EC-Council CEH, Microsoft SC-200 or AZ-500, Splunk Core Certified Power User, or GIAC (GCIA / GCIH).
- Prior experience in a hospital, healthcare group, or other 24x7 mission-critical workplace.
- Exposure to securing HIS/EMR, PACS, LIS, and connected medical devices, and to healthcare data standards (HL7, DICOM, FHIR) at a security-analysis level.
- Experience with digital forensics, malware analysis, or memory and disk artefact review.
- Experience with cloud security posture management, DLP, CASB, or email security gateways.
- Experience supporting ISO 27001, NABH, or regulatory audits with security evidence.
- Exposure to vulnerability management platforms (Nessus, Qualys, Rapid7, or similar).

📌 Soc Engineer (Kochi)
🏢 VPS Lakeshore
📍 Kochi

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: soc engineer (kochi) / kochi