EDR & SOC Analyst (Noida)

EDR & SOC Analyst (Noida)

29 Sep
|
protiviti india
|
Noida

29 Sep

protiviti india

Noida

Key Responsibilities

1. EDR Operations & Endpoint Security

1. Administer and operate the organization's EDR platform (Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, or equivalent).
2. Monitor endpoint security alerts, suspicious activities, malware detections, and behavioral indicators.
3. Investigate and validate endpoint threats, malicious processes, unauthorized access attempts, and potential compromises.
4. Conduct endpoint containment, isolation, remediation, and recovery activities.
5. Review and optimize EDR policies, detection rules, and response actions.
6. Coordinate endpoint security investigations with infrastructure and support teams.
7. Ensure coverage and health monitoring of all managed endpoints.
8. Support deployment and operational management of endpoint security controls.

2. Security Monitoring & SOC Operations

1. Monitor security alerts generated from SIEM, EDR, cloud security tools, email security platforms, and other monitoring solutions.
2. Perform triage, analysis, and prioritization of security events.
3. Validate alert severity, business impact, and escalation requirements.
4. Ensure security incidents are investigated and resolved within defined SLAs.
5. Review SOC-generated investigations and recommendations.
6. Coordinate activities with managed SOC providers for continuous monitoring and threat response.
7. Improve detection logic and monitoring coverage for emerging threats.

3. Support Incident Response & Investigation

1. Investigate cybersecurity incidents including malware, phishing, ransomware, account compromise, insider threats, and suspicious activities.
2.



Coordinate incident response activities across infrastructure, network, cloud, application, and business teams.
3. Support root cause analysis and documentation of security incidents.
4. Track remediation and corrective actions until closure.
5. Escalate major incidents in accordance with Incident Response procedures.
6. Participate in security incident simulations and tabletop exercises.

4. Threat Hunting & Threat Intelligence

1. Conduct proactive threat hunting across endpoints, identities, cloud workloads, and network activities.
2. Review threat intelligence feeds, IOC alerts, and emerging threat advisories.
3. Identify indicators of compromise, attacker techniques, and unusual system behaviors.
4. Recommend new detection use cases based on threat intelligence findings.
5. Assist in improving organizational cyber defense capabilities.

5. Vulnerability Management Support

1. Review endpoint security findings and vulnerability reports.
2. Coordinate remediation of critical vulnerabilities with technology teams.
3. Validate patching and mitigation activities.
4. Track aging vulnerabilities and provide regular reporting.
5. Support risk-based prioritization of security findings.

6. Reporting & Compliance Support

1. Prepare daily, weekly, and monthly security operations reports.
2. Maintain incident records,



investigation notes, forensic evidence, and audit trails.
3. Report key operational metrics including alerts, incidents, response times, and remediation status.
4. Support internal audits, client audits, ISO 27001, SOC, and regulatory compliance activities.
5. Contribute to security dashboards and executive reporting.

7. Continuous Improvement

1. Recommend improvements in monitoring, detection, response, and endpoint protection capabilities.
2. Assist in implementation of current cybersecurity technologies and security controls.
3. Develop and maintain SOC operational procedures and playbooks.
4. Participate in awareness initiatives and technical knowledge-sharing sessions.
5. Support maturity enhancement initiatives across security operations.

Qualifications & Experience

- Bachelors degree in information technology, Computer Science, Cybersecurity, or a related discipline.
- 4-7 years of hands-on cybersecurity operations experience.
- Experience working in SOC, MDR, EDR Operations, Incident Response, or Cyber Defense roles.
- Hands-on experience managing Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, Carbon Black, or similar EDR platforms.
- Experience with Microsoft Sentinel, Splunk, QRadar, LogRhythm, or other SIEM platforms.
- Familiarity with Windows, Linux, Active Directory, Azure, Microsoft 365, networking, and cloud security technologies.
- Experience investigating malware, phishing, ransomware, and endpoint security incidents.

Understanding of MITRE ATT&CK; Framework, Cyber Kill Chain, and incident response methodologies

📌 EDR & SOC Analyst (Noida)
🏢 protiviti india
📍 Noida

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: edr & soc analyst (noida) / noida

Subscribe to this job alert:

Get the latest job offers by email for: edr & soc analyst (noida) / noida