08 Sep
|
AlifCloud IT Consulting
|
Pune
08 Sep
AlifCloud IT Consulting
Pune
Title: SOC Analyst – L1
Location: Pune
Experience: 1–2Years
Employment Type: Full-Time
Shift: Rotational Shifts, including Night Shifts
About The Role
We are looking for a SOC Analyst – L1 to join our Security Operations Center team. The ideal candidate should have hands-on experience working with Microsoft Sentinel, be comfortable writing KQL queries, and have prior experience in an MSSP/SOC environment.
The candidate will be responsible for continuous security monitoring, initial alert investigation, incident triage, escalation, and supporting the incident response team.
Key Responsibilities
- Monitor security alerts and events using Microsoft Sentinel and other security monitoring tools.
- Perform L1 alert triage and investigate suspicious activities.
- Analyze logs from endpoints, firewalls, network devices, cloud environments, identity systems, and other security sources.
- Write and execute KQL (Kusto Query Language) queries for alert investigation, threat hunting, and log analysis.
- Perform initial investigation of security incidents and determine severity, impact, and priority.
- Identify false positives and perform appropriate alert closure with proper documentation.
- Escalate confirmed or complex incidents to L2/L3 / Incident Response teams.
- Have a basic understanding of Incident Response (IR) processes, including identification, containment, eradication, and recovery.
- Follow SOC playbooks, escalation procedures, and incident-handling processes.
- Maintain accurate investigation notes and incident documentation.
- Work with multiple customer environments in an MSSP setup while maintaining SLA requirements.
- Participate in continuous improvement of detection rules, use cases, and SOC processes.
- Stay updated on common attack techniques, vulnerabilities, and threat intelligence.
Mandatory Skills & Experience
- 1–3 years of experience in SOC / Cybersecurity Operations.
- Hands-on experience with Microsoft Sentinel is mandatory.
- Good understanding of KQL and ability to write queries for security investigations.
- Previous experience working in an MSSP / Managed SOC environment is mandatory.
- Experience handling and triaging security alerts/incidents.
- Basic understanding of Incident Response and SOC processes.
- Basic understanding of SIEM concepts and log analysis.
- Understanding of common security threats such as phishing, malware, brute-force attacks, credential attacks, suspicious PowerShell activity, and unauthorized access.
- Ability to analyze security events and correlate information from multiple log sources.
- Willingness to work in rotational shifts, including night shifts, weekends, and public holidays.
- Good communication and incident documentation skills.
Good to Have
- Experience with Microsoft Defender XDR / Defender for Endpoint / Defender for Identity.
- Knowledge of Azure and Microsoft Entra ID security.
- Experience with EDR/XDR platforms.
- Basic knowledge of network security, firewalls, IDS/IPS, VPN, DNS, and authentication protocols.
- Knowledge of MITRE ATT&CK; framework.
- Experience creating or tuning Sentinel analytics rules and detection use cases.
- Relevant certifications such as SC-200, Security+, CEH, or equivalent.
Candidate Profile
- We are looking for someone who:
- Can independently perform L1 alert triage.
- Is comfortable working with Microsoft Sentinel and KQL daily.
- Understands how an MSSP/SOC operates across multiple customers.
- Can differentiate between false positives and genuine security incidents.
- Has a security-first mindset and strong analytical skills.
- Is comfortable working under SLA-driven and shift-based SOC operations.
- Is willing to learn and progress toward an L2 SOC / Incident Response role.
Significant Requirement Candidates without hands-on Microsoft Sentinel and KQL experience, or without prior MSSP/SOC experience, may not be considered.
📌 SOC Analyst – (Pune)
🏢 AlifCloud IT Consulting
📍 Pune