23 Sep
|
Dynova | vCISO Services
|
India
23 Sep
Dynova | vCISO Services
India
Company Description
Dynova is an all-in-one cybersecurity service for startups and growing companies across the UAE and GCC, delivered via a virtual CISO on a monthly subscription model. Instead of fragmented security purchases, Dynova provides end-to-end ownership of security outcomes, with vCISOs directing priorities and engineers implementing controls, continuous penetration testing, and 24/7 SOC operations.
Role Overview
We are looking for an experienced Senior SOC Analyst to join our Cyber Defence function. The role will be responsible for advanced security monitoring, incident investigation and response, threat hunting, detection improvement, and supporting junior SOC analysts.
The successful candidate should have strong hands-on experience investigating security incidents across endpoints, identity, cloud, network, and application environments and be comfortable taking ownership of incidents from initial detection through containment and remediation.
Key Responsibilities
- Monitor, investigate, and respond to security alerts and incidents across SIEM, EDR/XDR, email security, identity, cloud, network, and application platforms.
- Perform Tier 2/Tier 3 investigation and escalation for complex security incidents.
- Conduct incident triage, determine scope and impact, identify root cause, and recommend containment and remediation actions.
- Perform threat hunting using SIEM, EDR/XDR, threat intelligence, and other security telemetry.
- Analyze suspicious authentication activity, malware, phishing, endpoint events, network activity, cloud events, and potential account compromise.
- Develop and improve SIEM detection rules, correlation rules, queries, dashboards, and alerting logic.
- Map detection and investigation activities against the MITRE ATT&CK; framework.
- Identify false positives and work with security engineering teams to improve detection quality.
- Support incident response activities, evidence collection, investigation timelines, and post-incident reviews.
- Create and maintain SOC playbooks, SOPs, escalation procedures, and investigation guides.
- Coordinate with IT, Cloud, DevOps, Application Security, IAM, and other teams during security incidents.
- Mentor junior SOC analysts and review escalated investigations.
- Support vulnerability, threat intelligence, and security monitoring activities.
- Produce incident reports, SOC metrics, management reports, and security trend analysis.
- Participate in an on-call / 24x7 SOC operating model where required.
Required Experience & Skills
- 4–7+ years of cybersecurity experience, with significant hands-on SOC/incident response experience.
- Strong experience with enterprise SIEM platforms, preferably Elastic Security, Microsoft Sentinel, Splunk, or similar.
- Robust experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, Cortex XDR, or equivalent.
- Strong understanding of:
- Windows and Linux security
- Microsoft Entra ID / Active Directory
- AWS and/or Azure security logs
- Network security and common protocols
- Email security and phishing investigations
- IAM and authentication attacks
- Experience investigating compromised accounts, malware, suspicious PowerShell, lateral movement, privilege escalation, and cloud security events.
- Ability to write and analyze queries using KQL, ES|QL, EQL, Lucene, SPL, or similar query languages.
- Good understanding of MITRE ATT&CK; and common attacker TTPs.
- Strong incident documentation and stakeholder communication skills.
- Willingness to work in shifts
📌 Senior SOC Analyst (India)
🏢 Dynova | vCISO Services
📍 India