We are urgently hiring for SOC L2 Engineer at Delhi Location.
Job Summary:
We are looking for an experienced SOC L2 Analyst with 5+ years of experience in Security Operations, incident management, threat monitoring, and security event analysis. The candidate should have strong hands-on experience with Micro Focus/ArcSight SIEM, including correlation rules, use cases, log analysis, incident investigation, and troubleshooting.
Key Responsibilities:
- Monitor and analyze security events and alerts using ArcSight SIEM.
- Perform L2-level investigation and analysis of security incidents.
- Investigate suspicious activities, security breaches, malware, unauthorized access, and other threats.
- Develop, fine-tune, and troubleshoot ArcSight correlation rules and SIEM use cases.
- Perform log analysis across various security devices and technologies.
- Correlate events from firewalls, IDS/IPS, endpoint security, servers, applications, and network devices.
- Conduct incident triage, determine severity, and initiate appropriate response/escalation.
- Perform root-cause analysis and provide recommendations for incident remediation.
- Identify false positives and continuously improve alert quality and SOC monitoring.
- Create and maintain incident reports, investigation reports, and SOC documentation.
- Coordinate with L1 analysts, Incident Response, Network, System, and other security teams for incident resolution.
- Support threat hunting and identification of indicators of compromise (IOCs).
- Participate in SOC process improvement,
security use-case development, and operational activities.
- Ensure adherence to defined SLA, incident management, and SOC processes.
Mandatory Technical Skills:
- 5+ years of experience in SOC / Cyber Security Operations.
- Strong hands-on experience with ArcSight SIEM is mandatory.
- Experience in ArcSight Enterprise Security Manager (ESM).
- Good understanding of ArcSight correlation rules, filters, dashboards, connectors, and event management.
- Strong knowledge of SIEM monitoring and log correlation.
- Experience in investigating security incidents and performing event/alert analysis.
- Good understanding of TCP/IP, DNS, HTTP/HTTPS, VPN, firewalls, IDS/IPS, and networking concepts.
- Knowledge of Windows and Linux security events/logs.
- Understanding of common cyber threats, attack techniques, and MITRE ATT&CK; framework.
- Experience with incident management and SOC escalation procedures.
Valuable to Have:
- Experience with other SIEM tools such as Splunk, IBM QRadar, Microsoft Sentinel, etc.
- Knowledge of EDR/XDR solutions.
- CEH, Security+, CySA+, CISSP or other relevant cybersecurity certifications.
- Experience in threat hunting and vulnerability/security monitoring.
Key Requirement: Candidates must have strong hands-on ArcSight experience. Candidates with only generic SOC/SIEM experience but without relevant ArcSight exposure should not be considered.
Immediate candidates only , please share your resume at
[email protected]
📌 SOC (Delhi)
🏢 CMS Computers
📍 Delhi