08 Sep
|
AlifCloud IT Consulting
|
Pune
08 Sep
AlifCloud IT Consulting
Pune
Title: SOC Analyst – L1
Location: Pune
Experience: 1–2Years
Employment Type: Full-Time
Shift: Rotational Shifts, including Night Shifts
About the Role
We are looking for a SOC Analyst – L1 to join our Security Operations Center team. The ideal candidate should have hands-on experience working with Microsoft Sentinel, be comfortable writing KQL queries, and have prior experience in an MSSP/SOC environment.
The candidate will be responsible for continuous security monitoring, initial alert investigation, incident triage, escalation, and supporting the incident response team.
Key Responsibilities
Monitor security alerts and events using Microsoft Sentinel and other security monitoring tools.
Perform L1 alert triage and investigate suspicious activities.
Analyze logs from endpoints, firewalls, network devices, cloud environments, identity systems, and other security sources.
Write and execute KQL (Kusto Query Language) queries for alert investigation, threat hunting, and log analysis.
Perform initial investigation of security incidents and determine severity, impact, and priority.
Identify false positives and perform appropriate alert closure with proper documentation.
Escalate confirmed or complex incidents to L2/L3 / Incident Response teams.
Have a basic understanding of Incident Response (IR) processes, including identification, containment, eradication, and recovery.
Follow SOC playbooks, escalation procedures, and incident-handling processes.
Maintain accurate investigation notes and incident documentation.
Work with multiple customer environments in an MSSP setup while maintaining SLA requirements.
Participate in continuous improvement of detection rules, use cases, and SOC processes.
Stay updated on common attack techniques, vulnerabilities, and threat intelligence.
Mandatory Skills & Experience
1–3 years of experience in SOC / Cybersecurity Operations.
Hands-on experience with Microsoft Sentinel is mandatory.
Good understanding of KQL and ability to write queries for security investigations.
Previous experience working in an MSSP / Managed SOC environment is mandatory.
Experience handling and triaging security alerts/incidents.
Basic understanding of Incident Response and SOC processes.
Basic understanding of SIEM concepts and log analysis.
Understanding of common security threats such as phishing, malware, brute-force attacks, credential attacks, suspicious PowerShell activity, and unauthorized access.
Ability to analyze security events and correlate information from multiple log sources.
Willingness to work in rotational shifts, including night shifts, weekends, and public holidays.
Good communication and incident documentation skills.
Good to Have
Experience with Microsoft Defender XDR / Defender for Endpoint / Defender for Identity.
Knowledge of Azure and Microsoft Entra ID security.
Experience with EDR/XDR platforms.
Basic knowledge of network security, firewalls, IDS/IPS, VPN, DNS, and authentication protocols.
Knowledge of MITRE ATT&CK; framework.
Experience creating or tuning Sentinel analytics rules and detection use cases.
Relevant certifications such as SC-200, Security+, CEH, or equivalent.
Candidate Profile
We are looking for someone who:
Can independently perform L1 alert triage.
Is comfortable working with Microsoft Sentinel and KQL daily.
Understands how an MSSP/SOC operates across multiple customers.
Can differentiate between false positives and genuine security incidents.
Has a security-first mindset and strong analytical skills.
Is comfortable working under SLA-driven and shift-based SOC operations.
Is willing to learn and progress toward an L2 SOC / Incident Response role.
Significant Requirement
Candidates without hands-on Microsoft Sentinel and KQL experience, or without prior MSSP/SOC experience, may not be considered.
📌 SOC Analyst (Pune)
🏢 AlifCloud IT Consulting
📍 Pune