01 Oct
|
the Company: ACPL (www.acpl.com)
|
Gurugram
01 Oct
the Company: ACPL (www.acpl.com)
Gurugram
Competency:
Detection Engineering, Playbook Creation, CrowdStrike, Threat hunting - Proactive and Reactive, IRYears of experience required:
Min 4 Years :
About the Company: ACPL (www.acpl.com) We at ACPL are Cyber Security specialists and help corporates with their complete cycle of setting up the Cyber security platform. Right from selecting the adaptable security tools to the deployment of the same and then providing dedicated cybersecurity services.
Established in 1990, ACPL is the developer of India’s first antivirus software “SmartDog”. We offer our services and solutions by integrating complex technologies offered by the leading IT companies through strategic partnerships. Our solutions and services are majorly focused on the most challenging industry verticals like BFSI, Manufacturing, Telecommunication, Retail, Healthcare, IT/ ITES, Power, Media Education, Distribution and more.
We are $70 million company with PAN India presence with services across ASIA and a branch office in Singapore. We are a team of 300+ highly qualified professionals having certifications like CISSP, CISA, GICH etc.
Apart from winning various Industry awards and recognitions ACPL is 100% RBA Compliant and a certified “Outstanding place to work”.
Job Summary
We are looking for a Senior SOC Analyst (L2/L3) with strong expertise in Detection Engineering, Threat Hunting, Incident Response, Playbook creation and Cortex XSIAM/NG-SIEM. The ideal candidate will be responsible for developing and tuning detection rules,
investigating security incidents, reducing false positives, creating SOC playbooks, and driving continuous SOC improvements.
Key Responsibilities
• Develop, tune, and optimize SIEM/XSIAM detection rules and use cases.
• Perform proactive and reactive threat hunting.
• Lead incident response activities including investigation, containment, eradication, and recovery.
• Create and maintain SOC investigation and incident response playbooks.
• Conduct Root Cause Analysis (RCA) and recommend security improvements.
• Reduce false positives through alert tuning and detection optimization.
• Write and optimize queries using KQL, SPL, SQL, and automate tasks using PowerShell/Python.
• Collaborate with MDR teams and leverage threat intelligence aligned with the MITRE ATT&CK; framework.
• Drive SOC process improvements, automation, and KPI optimization (MTTD, MTTR, SLA).
Required Skills / Technologies
• Detection Engineering • Cortex XSIAM / NG-SIEM • Threat Hunting (Proactive & Reactive) • Incident Response (IR) • Playbook Creation • Root Cause Analysis (RCA) • False Positive Reduction • KQL, SPL, SQL • PowerShell or Python • MDR Operations • MITRE ATT&CK; Framework
Preferred Exposure
• 3–8 years of experience in SOC Operations (L2/L3). • Hands-on experience with Cortex XSIAM/XDR or enterprise SIEM platforms. • Relevant certifications such as CEH, CySA+, GCIH, SC-200, or Palo Alto certifications are preferred.
📌 Senior SOC Analyst (Gurugram)
🏢 the Company: ACPL (www.acpl.com)
📍 Gurugram