30 Sep
|
Rakuten Symphony
|
Bengaluru
30 Sep
Rakuten Symphony
Bengaluru
Job Title: SOC Analyst (L2)
Department: Cyber Defense Operations
Location: Bangalore, India
About the Team/Department:
You will be at the forefront of the most significant shift in cyber defense history. We offer a platform for you to innovate, experiment with AI, and build a world-class security capability that protects critical infrastructure. If you are a creative, hands-on leader who thrives on solving the impossible problems of the AI-attack era, we want to hear from you.
Position Summary
We are seeking a highly technical and innovative SOC Analyst (L2) to serve as a key architect of our future-ready Security Operations Center. In this role, you will go beyond traditional monitoring; you will actively participate in the transformation of our SOC to counter autonomous,
AI-driven cyber threats. You will leverage LLMs and AI-powered security tools to detect,
analyze, and neutralize advanced adversaries. Reporting to the SOC Lead, you will be a hands-
on contributor to our capacity development, refining our defenses to ensure we remain resilient against the next generation of machine-speed attacks.
Key Responsibilities
- AI-Driven Threat Defense: Utilize LLMs and AI-augmented security platforms to accelerate threat hunting, incident triage, and forensic analysis. Develop workflows to identify and respond to autonomous AI-based attacks.
- SOC Transformation & Enhancement: Actively contribute to the SOC’s capability roadmap. Recommend and implement structural improvements to our toolsets and processes to ensure we are equipped to handle the evolving threat landscape.
- Container & K8s Security Operations: Perform deep-dive analysis into containerized environments and Kubernetes clusters. Implement security controls that defend against container-specific exploits and automated lateral movement.
- Capacity Development: Participate in the continuous training and upskilling of the SOC team. Translate your technical findings into new playbooks and SOPs that elevate the entire team's response maturity
- Advanced Incident Response: Lead the investigation of complex incidents. Use your understanding of "Defense in Depth" to identify gaps in our environment and propose architectural hardening.
- Security Engineering: Collaborate with the L3 Manager to tune detection logic and integrate AI-based feedback loops into our SIEM/SOAR infrastructure.
- Offensive Security Research: Apply an "OffSec" mindset to simulate and test our defenses against AI-powered attack tools, ensuring our response is faster and more precise than the adversary.
Required Qualifications
- Bachelor’s degree in Computer Science, Cyber Security, or equivalent.
- 5 - 8 years of experience in a SOC, incident response, or security engineering role.
- Strong understanding of SIEM/SOAR ecosystems and how to optimize them for AI-driven detection.
- Relevant certifications (e.g., GCIH, GCSA, CKAD, CKS, or AI-Security specific certifications)
Preferred Qualifications
- Experience in the Telecommunications sector (e.g., understanding of 5G security, NFV,and signaling protocols).
- Experience in developing custom AI/ML models or fine-tuning LLMs for specific security use cases.
- Demonstrable experience in "Red Teaming" or participating in high-level CTF competitions.
- Experience with Infrastructure as Code (IaC) and DevSecOps pipelines.
Core Competencies
- AI & LLM Proficiency: Practical experience in using LLMs for security tasks (e.g., code analysis, log interpretation, playbook automation, or threat intelligence summarization).
- Technical Depth: Expert-level knowledge of Linux, containerization (Docker), and Kubernetes (K8s) security.
- Analytical & Investigative Skills: Strong ability to perform root-cause analysis on complex, non-signature-based attacks.
- Security Architecture: A firm understanding of defense-in-depth principles and how to apply them to up-to-date, distributed network architectures.
- Automation Mindset: Proven ability to automate manual tasks using Python, Go, or Bash. You must be comfortable building "security-as-code" solutions.
- Communication: Exceptional written and verbal communication skills, with the ability to articulate technical security threats to both technical and non-technical stakeholders.
📌 Staff Engineer SOC (Bengaluru)
🏢 Rakuten Symphony
📍 Bengaluru