Senior SOC Analyst / Cyber Security Analyst (Noida)

Senior SOC Analyst / Cyber Security Analyst (Noida)

27 Sep
|
Shivtel Communications
|
Noida

27 Sep

Shivtel Communications

Noida

About Fonada

Fonada is a leading AI-powered CPaaS platform helping enterprises transform customer communication through Voice, SMS, WhatsApp Business API, Contact Center, IVR, AI Voice Bots, Chatbots, and Conversational AI solutions. We are committed to building secure, scalable, and reliable communication platforms for businesses across industries.

About the Role

Fonada is looking for an experienced Senior SOC Analyst / Cyber Security Analyst with strong hands-on expertise in SOC Operations, SIEM, Incident Response, EDR/XDR, Threat Detection, Threat Hunting, Cloud Security and Vulnerability Management.

The ideal candidate should have practical experience investigating security incidents, analysing security logs, responding to threats and working with SIEM, EDR/XDR, identity and cloud security platforms.

Key Responsibilities

SOC Operations & Security Monitoring

- Monitor and investigate alerts from SIEM, EDR/XDR, firewall, WAF, email and cloud security platforms.
- Correlate security events and identify suspicious activity, IOCs and IOAs.
- Investigate abnormal authentication, endpoint, network and user behaviour.
- Tune detection rules and reduce false positives.

Incident Response

- Handle incidents through detection, investigation, containment, eradication, recovery and post-incident analysis.
- Investigate malware, phishing, ransomware, account compromise, credential theft, brute-force and password-spraying incidents.
- Perform root-cause analysis and establish incident timelines.
- Coordinate endpoint isolation, credential resets, session revocation and account restrictions.
- Prepare technical incident reports and management summaries.

SIEM & Log Analysis

- Analyse Windows, Linux, network, firewall, WAF, authentication and cloud logs.
- Develop and use SIEM queries for investigations.
- Work with Windows Security Events including Event ID 4624 and 4625.
- Identify brute-force, password-spraying,



suspicious authentication and malicious activity.
- Maintain security dashboards, alerts and reports.

Threat Detection & Hunting

- Conduct proactive threat hunting across endpoint, network, identity and cloud environments.
- Use MITRE ATT&CK; to map attacker behaviour.
- Investigate attacker TTPs and improve detection capabilities based on threat intelligence and incidents.

EDR/XDR & Endpoint Security

- Investigate alerts using CrowdStrike, Microsoft Defender for Endpoint or equivalent EDR/XDR platforms.
- Analyse process trees, command-line activity, files and network connections.
- Validate malicious activity versus false positives.
- Coordinate endpoint isolation, remediation and recovery.

Identity & Cloud Security

- Investigate suspicious sign-ins and identity incidents in Microsoft Entra ID / Azure AD.
- Analyse risky sign-ins, impossible-travel alerts and unusual authentication.
- Investigate compromised accounts and unauthorised access.
- Perform session/token revocation, password resets and account restrictions.
- Monitor cloud security events.

Email & Phishing Security

- Investigate phishing, spoofing and Business Email Compromise.
- Analyse email headers and SPF, DKIM and DMARC.
- Identify malicious domains and suspicious sender infrastructure.
- Investigate malicious mailbox rules and external forwarding.

Network & WAF Security

- Analyse firewall, WAF and network security logs.
- Investigate abnormal traffic and suspicious IPs.
- Differentiate DDoS, credential stuffing and brute-force attacks.




- Coordinate mitigation with technical teams.

Vulnerability Management

- Analyse reported CVEs and determine impact on the environment.
- Validate vulnerability findings.
- Prioritise vulnerabilities using CVSS, asset criticality, exploitability, exposure and business impact.
- Coordinate and validate remediation.

Reporting

- Prepare technical investigation and incident reports.
- Document timelines, root causes, findings and remediation.
- Maintain investigation records and track metrics including MTTR.

Required Skills & Qualifications

- 5+ years of experience in Cyber Security, SOC Operations or Security Operations.
- Strong hands-on experience with SIEM and Incident Response.
- Experience with Splunk, Microsoft Sentinel or equivalent SIEM.
- Experience with EDR/XDR, such as CrowdStrike or Microsoft Defender.
- Strong understanding of MITRE ATT&CK; and Cyber Kill Chain.
- Experience investigating malware, phishing, account compromise and suspicious endpoint activity.
- Strong knowledge of Microsoft Entra ID / Azure AD and Active Directory.
- Experience with Windows Security Events and authentication logs.
- Knowledge of SPF, DKIM and DMARC.
- Knowledge of network security, firewalls, WAF and DDoS.
- Experience with vulnerability management, CVE analysis and CVSS.
- Knowledge of threat detection and threat hunting.
- Experience with SPL and/or KQL.
- Solid analytical, troubleshooting, documentation and communication skills.

Preferred Qualifications

- Certifications such as CEH, Security+, CySA+, GCIH, CISSP, SC-200 or equivalent.
- Experience with threat intelligence and SOAR/security automation platforms.
- Experience developing or tuning SIEM detection rules.
- Cloud security monitoring experience.
- Experience in SaaS, CPaaS, Telecom or Technology environments.

Interested candidates can share their updated CV with Current CTC at [email protected].

📌 Senior SOC Analyst / Cyber Security Analyst (Noida)
🏢 Shivtel Communications
📍 Noida

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior soc analyst / cyber security analyst (noida) / noida

Subscribe to this job alert:

Get the latest job offers by email for: senior soc analyst / cyber security analyst (noida) / noida