30 Sep
|
Qualitest
|
Bengaluru
30 Sep
Qualitest
Bengaluru
SOC Analyst (2-5 Years)
Location: Bangalore
Work Mode : Work from Office Module
Experience: 2-5 Years
Shift: Rotational Shifts
About the Role
We are looking for an experienced L2 SOC Engineer with 2–5 years of hands-on experience in security monitoring, incident investigation, SIEM operations,
perform alert management, conduct initial incident qualification, and escalate confirmed security incidents to the SOC Manager.
Key Responsibilities
Continuously monitor and analyze security alerts generated by SIEM, EDR, and other security tools.
Perform L2-level triage and detailed investigation of security incidents.
Correlate events from multiple sources to identify attack patterns, indicators of compromise, and suspicious activity.
Analyze endpoint telemetry, process execution, command-line activity, file behavior, registry changes, and network connections using EDR tools.
Escalate validated security incidents to the SOC Lead/Manager as per defined procedures.
Perform false-positive and false-negative analysis and recommend improvements to detection rules.
Create and manage incident tickets in ITSM tools, ensuring accurate documentation of alerts, indicators, and investigation findings.
Report infrastructure or security tool issues to the relevant IT support teams.
Identify gaps in monitoring and recommend new detection scenarios based on emerging threats.
Support security operations activities and adhere to established SLA and incident response procedures.
Required Skills & Experience
Working knowledge of SIEM use cases, correlation rules, log-source onboarding, parser issues, and rule tuning.
Robust experience using EDR tools such as CrowdStrike, McAfee EDR, or similar platforms.
Strong knowledge of TCP/IP networking, network traffic analysis, and event log analysis.
Familiarity with the MITRE ATT&CK; framework and its application to alert investigation and threat detection.
Understanding of incident response processes, evidence handling, containment, remediation, and root-cause analysis.
Knowledge of ITIL practices, including Incident, Problem, and Change Management.
Good analytical, troubleshooting, and communication skills.
Preferred Qualifications
CEH (Certified Ethical Hacker) or similar certification.
Exposure to SOC operations, incident handling, and security monitoring processes.
Ability to work effectively in a 24x7 rotational shift environment.
📌 SOC Analyst (Bengaluru)
🏢 Qualitest
📍 Bengaluru