12 Sep
|
Wipro
|
Bengaluru
Job Title: CYBER SECURITY ANALYST L2
City: Bengaluru
State/Province: Karnataka
Posting Start Date: 9/11/26
Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO) is a leading technology services and consulting company focused on building innovative solutions that address clients’ most complex digital transformation needs. Leveraging our holistic portfolio of capabilities in consulting, design, engineering, and operations, we help clients realize their boldest ambitions and build future-ready, sustainable businesses. With over 230,000 employees and business partners across 65 countries, we deliver on the promise of helping our customers, colleagues, and communities thrive in an ever-changing world. For additional information, visit us at www.wipro.com.
Role Purpose
The purpose of this role is to develop and test software modules based on client requirements and prepare project documentation while coordinating with cross-functional teams to ensure quality delivery.
͏
Areas of responsibility
͏
Gathering of requirements-Assist in conducting workshops and discussions with client stakeholders to gather business process requirements.
Coding and Configuration-"Develop and deliver code for assigned modules, in alignment with client requirements ensuring proper integration with system components.
͏
Testing and Trial Runs-"Execute testing for assigned modules, validate functionality across required interactions, and participate in User Acceptance Testing (UAT) sessions.
Implementation-Participate in implementation of software application and its integration with other systems to ensure stability.
Maintain Documentation-Prepare detailed reports and documentation on project specifications, activities, and status, while presenting information using flowcharts, layouts, diagrams, code comments, and clear, well-structured code.
͏
Stakeholder Collaboration-Collaborate with cross functional teams to understand requirements, support development activities, check system compatibility, and ensure solutions meet expected standards.
SOC Analyst – Level 2 (Microsoft Security Stack)
Key Responsibilities
Threat Detection & Incident Response
Act as the primary escalation point for L1 SOC analysts for complex and high-severity security incidents
Perform advanced triage, investigation, and root cause analysis of security alerts and incidents
Conduct deep-dive analysis of security events, correlating data across multiple sources to identify threats
Execute incident containment, eradication, and recovery procedures in accordance with established playbooks and IR frameworks
Document incidents thoroughly, including timeline, impact assessment, remediation steps, and lessons learned
Participate in on-call rotations for after-hours incident response
Microsoft Azure Sentinel (Microsoft Sentinel)
Develop, tune, and optimize KQL (Kusto Query Language) queries for threat detection and hunting
Create, manage, and fine-tune analytic rules, workbooks, and dashboards in Microsoft Sentinel
Design and implement SOAR playbooks using Logic Apps for automated incident response
Configure and manage data connectors to ingest logs from diverse sources (Azure, on-premises, third-party)
Develop and maintain custom hunting queries and threat intelligence integrations
Perform regular tuning to reduce false positives and improve detection accuracy
Create and maintain Sentinel Workbooks for reporting and visualization
Microsoft Defender Suite
Monitor, investigate, and respond to alerts from:
Microsoft Defender for Endpoint (MDE) – Endpoint detection, advanced hunting, live response
Microsoft Defender for Office 365 – Email security, phishing analysis, Safe Links/Attachments
Microsoft Defender for Identity – Identity-based threat detection, lateral movement analysis
Microsoft Defender for Cloud Apps (MCAS) – Shadow IT discovery, cloud app security policies
Microsoft Defender for Cloud – Cloud workload protection, security posture management
Manage Automated Investigation and Response (AIR) capabilities
Perform advanced hunting using KQL across Microsoft 365 Defender portal
Manage attack surface reduction (ASR) rules and endpoint security policies
Azure & Cloud Security
Monitor and respond to security events in Microsoft Defender for Cloud (formerly Azure Security Center)
Assess and remediate Azure Secure Score recommendations
Investigate alerts related to Azure AD / Entra ID – risky sign-ins, impossible travel, identity protection
Monitor Conditional Access policies , MFA events, and privileged identity management (PIM) alerts
Support security for Azure resources including VMs, Storage Accounts, Key Vaults, NSGs, and Azure Firewall
Review and analyze Azure Activity Logs, Diagnostic Logs, and NSG Flow Logs
Threat Hunting & Intelligence
Conduct proactive threat hunting to identify advanced persistent threats (APTs) and unknown threats
Leverage MITRE ATT&CK; framework to map adversary TTPs and improve detection coverage
Integrate and operationalize threat intelligence feeds within Microsoft Sentinel
Research emerging threats, vulnerabilities, and attack vectors relevant to the organization
Create threat hunting hypotheses and execute structured hunting campaigns
Process Improvement & Mentorship
Mentor and guide L1 analysts , providing training on investigation techniques and tools
Develop and update SOC playbooks, runbooks, and standard operating procedures (SOPs)
Identify gaps in detection and recommend improvements to security monitoring
Participate in purple team exercises and tabletop simulations
Provide detailed shift handover reports and maintain incident documentation
Contribute to post-incident reviews and drive remediation tracking
Reporting & Compliance
Generate weekly/monthly SOC metrics and KPI reports for management
Support audit and compliance requirements (ISO 27001, SOC 2, NIST, GDPR, HIPAA, etc.)
Maintain accurate records in ticketing/ITSM tools (ServiceNow, Jira, etc.)
Present findings and recommendations to technical and non-technical stakeholders
Required Skills & Qualifications
Technical Skills
3–6 years of experience in a Security Operations Center (SOC) or cybersecurity role with at least 1–2 years at L2 level
Strong hands-on experience with Microsoft Sentinel – analytics rules, workbooks, playbooks,
data connectors, and hunting
Proficiency in KQL (Kusto Query Language) – writing complex queries for detection and investigation
Expert-level knowledge of Microsoft Defender for Endpoint, Office 365, Identity, and Cloud Apps
Strong understanding of Microsoft Defender for Cloud and Azure security services
In-depth knowledge of Azure Active Directory / Microsoft Entra ID security features (Conditional Access, PIM, Identity Protection)
Solid understanding of network protocols (TCP/IP, DNS, HTTP/S, SMTP, SMB), firewall logs , and packet analysis
Experience with email security analysis – header analysis, phishing investigation, malware triage
Familiarity with SIEM/SOAR concepts , log management, and event correlation
Understanding of malware analysis fundamentals – static/dynamic analysis, sandboxing
Knowledge of Windows and Linux operating systems, event logs, and security hardening
Experience with PowerShell scripting for automation and investigation
Frameworks & Methodologies
Strong understanding of MITRE ATT&CK;, Cyber Kill Chain.
Knowledge of OWASP Top 10 and common web application vulnerabilities
Understanding of Zero Trust architecture principles
Soft Skills
Excellent analytical thinking and problem-solving abilities
Strong communication skills – ability to articulate complex technical findings to diverse audiences
Ability to work under pressure and manage multiple incidents simultaneously
Strong attention to detail and documentation skills
Team player with a collaborative mindset
Self-motivated with a continuous learning attitude
Preferred / Good-to-Have Skills
Experience with Microsoft Copilot for Security
Familiarity with Azure Logic Apps / Power Automate for SOAR automation
Experience with additional SIEM tools (Splunk, QRadar, Chronicle)
Knowledge of cloud security for multi-cloud environments (AWS, GCP)
Experience with vulnerability management tools (Qualys, Tenable, Rapid7)
Familiarity with EDR/XDR platforms beyond Microsoft (CrowdStrike, SentinelOne, Carbon Black)
Understanding of DevSecOps principles and CI/CD pipeline security
Experience with digital forensics and incident response (DFIR)
Knowledge of scripting languages – Python, PowerShell, Bash
Familiarity with ITSM tools – ServiceNow, Jira Service Management
Certifications (Preferred)
Certification
Issuing Body
SC-200 : Microsoft Security Operations Analyst
Microsoft
SC-900 : Microsoft Security, Compliance, and Identity Fundamentals
Microsoft
AZ-500 : Microsoft Azure Security Technologies
Microsoft
MS-500 : Microsoft 365 Security Administration
Microsoft
CompTIA CySA+
CompTIA
CompTIA Security+
CompTIA
CEH – Certified Ethical Hacker
EC-Council
Mandatory Skills: Cloud Security Engineering .
Experience: 3-5 Years .
Reinvent your world. We are building a up-to-date Wipro. We are an end-to-end digital transformation partner with the boldest ambitions. To realize them, we need people inspired by reinvention. Of yourself, your career, and your skills. We want to see the constant evolution of our business and our industry. It has always been in our DNA - as the world around us changes, so do we. Join a business powered by purpose and a place that empowers you to design your own reinvention.
📌 CYBER SECURITY ANALYST (Bengaluru)
🏢 Wipro
📍 Bengaluru