Soc Analyst (Bengaluru)

Soc Analyst (Bengaluru)

19 Sep
|
PwC India
|
Bengaluru

19 Sep

PwC India

Bengaluru

Key Responsibilities:

- Operate under the SOC function, reporting to the SOC Manager, with responsibility for developing and fine-tuning detection logic and correlation rules in Splunk SIEM and other detection platforms (e.g., Splunk ES, UBA, SOAR)
- Collaborate actively with the Global Security Content and Response Automation Team (SCRAT) to enhance detection logic and response automation
- Participate in daily SOC stand-up calls and provide support for complex query development and troubleshooting
- Oversee the quality and effectiveness of detection logic, continuously reducing false positives and improving alert fidelity through iterative tuning and feedback
- Work closely with SOC Engineering to ensure necessary telemetry and event sources are available for effective threat detection
- Stay up to date with emerging threats and attacker techniques, translating threat intelligence into actionable detection content
- Maintain comprehensive documentation for detection logic, including rule rationale, expected behaviour, and tuning history.
- Perform threat coverage gap analysis and mapping using frameworks such as MITRE ATT&CK;
- Support threat hunting initiatives by developing custom queries, dashboards, and analytics
- Mentor junior Splunk administrators on data ingestion, parsing, indexing, and troubleshooting.
- Participate in red/blue/purple team exercises to validate and improve detection effectiveness.




- Assist in the development of detection-related KPIs and metrics for SOC performance reporting.

Skills and Experience:

- 6-8 years of experience in SOC, threat detection, or security engineering roles
- Advanced proficiency in analysing security events across both Linux and Windows environments, including log source normalization and enrichment
- Strong command of SIEM query languages (e.g., Splunk SPL, KQL, CrowdStrike Query Language), with the ability to write complex queries for threat detection, hunting, and anomaly identification
- Proficiency in scripting languages such as Python and PowerShell, with experience automating detection logic and integrating with orchestration workflows
- Demonstrated expertise in building and maintaining detection content, including correlation searches and risk-based alerting
- Deep understanding of the MITRE ATT&CK; framework and the ability to accurately map detection logic to specific TTPs
- Hands-on experience with the Splunk ecosystem, including Enterprise Security (ES), User Behaviour Analytics (UBA), SOAR, and apps like Torq
- Strong foundational knowledge of cybersecurity principles, threat landscapes, and incident response methodologies
- Excellent communication and collaboration skills, with the ability to work effectively across SOC, IR, and global engineering teams
- Robust analytical and problem-solving abilities
- Splunk certifications (e.g., Admin, Power User, Developer) are a plus

📌 Soc Analyst (Bengaluru)
🏢 PwC India
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: soc analyst (bengaluru) / bengaluru