SOC Analyst —
Position: SOC Analyst (Level 1 / Level 2)
Location: Pune/ Office
Employment Type: Full time
Reports To: SOC Manager
About the Role
We are looking for a SOC Analyst to join our Security Operations Center. You will monitor, investigate, and respond to security events across client environments, working with a mix of enterprise tools and cloud platforms. This role demands equal parts technical depth and communication clarity — you will be the person clients and internal stakeholders hear from during an incident, and your written reports need to be as sharp as your investigation skills.
What You Will Do
- Monitor security alerts across SIEM, EDR, email security, and DNS filtering platforms on a continuous basis
- Triage and investigate security events, distinguishing true positives from false positives with documented rationale
- Respond to and contain incidents per defined runbooks, escalating Sev 1 and Sev 2 events to senior analysts and the CISO
- Produce clear, concise incident reports for both technical audiences and non-technical stakeholders — executives should be able to read your summary without a security background
- Communicate proactively with clients during active incidents: status updates, containment actions taken, next steps, timelines
- Conduct phishing email analysis and report findings through defined channels
- Perform log analysis across Microsoft 365, Entra ID, AWS CloudTrail, and endpoint management platforms
- Maintain accurate, real-time documentation in ticketing systems throughout every investigation
- Participate in post-incident reviews and contribute to runbook improvements
- Support vulnerability tracking and coordinate patch status updates with system owners
What We're Looking For
Technical Skills
- 1–3 years in a SOC, helpdesk security,
or IT security role (Level 1); 3–5 years for Level 2
- Hands-on experience with SIEM platforms (Microsoft Sentinel, Splunk, or equivalent)
- Familiarity with Microsoft 365 security tools — Defender for Endpoint, Defender for Office 365, Purview Audit, Entra ID sign-in logs
- Understanding of common attack frameworks: MITRE ATT&CK;, kill chain methodology
- Basic knowledge of networking fundamentals — DNS, HTTP/S, TCP/IP, firewall logs
- Experience reading and interpreting Windows Event Logs, Azure/Entra sign-in logs, and email headers
- Exposure to cloud environments (AWS or Azure) is an advantage
Communication Skills — Non-Negotiable
- Writes clearly and professionally in English — no jargon when the audience doesn't need it
- Can produce an incident summary that a CFO or CEO can act on, and a technical timeline that an engineer can follow
- Comfortable giving real-time verbal updates to clients during active incidents, including delivering bad news calmly and clearly
- Responds promptly and transparently — stakeholders are never left wondering what is happening
- Understands that communication during an incident is itself a security control
Mindset and Behaviour
- Stays calm under pressure — incidents are not the time to go quiet or speculate publicly
- Curious and methodical — follows evidence, not assumptions
- Takes ownership of tickets end-to-end; does not hand off without context
- Asks good questions when scope is unclear rather than proceeding on assumptions
- Collaborative — works effectively across time zones with US and India teams
Preferred Certifications
- CompTIA Security+
- SC-200 (Microsoft Security Operations Analyst)
- CISA
- GCIH (GIAC Certified Incident Handler) — Level 2
Pay: ₹280,000.00 - ₹350,000.00 per year Work Location: Hybrid remote in Pune, Maharashtra 411046
📌 Soc Analyst/ (Pune)
🏢 Flynaut
📍 Pune