04 Oct
|
Inmar Technologies
|
Hyderabad
04 Oct
Inmar Technologies
Hyderabad
Position Information:
Job Title: Senior SOC Analyst(Manager/Lead)
Function: Cybersecurity / Security Operations Center
Career Level / Grade
Employment Type: Full-time
Employment Status: Regular Employee
Work Location: Hyderabad, Telangana, India
Work Arrangement: [On-site / Hybrid, in accordance with company policy]
Reports To: Senior Manager, Security Operations Center
Position Summary:
The Senior SOC Analyst is a senior individual contributor within Inmar's Security Operations Center (SOC), responsible for advanced threat detection, investigation, incident response, threat hunting, and detection engineering.
The role serves as a technical resource within the SOC, helping identify and respond to security threats while continuously strengthening Inmar's security monitoring and response capabilities. The Senior SOC Analyst develops advanced detection logic, leads complex security investigations, performs proactive threat hunting, and contributes to improvements in SOC processes, tools, workflows, and playbooks.
The position also provides technical guidance and mentorship to SOC analysts and partners closely with Cybersecurity Engineering and other technology teams to improve the configuration, effectiveness, and reliability of security platforms.
This role operates in a global environment and requires effective collaboration with colleagues and stakeholders across India and other Inmar locations.
Key Responsibilities The percentages below are intended to indicate the general allocation of responsibilities. Actual allocation may vary based on security incidents, operational priorities, business requirements, and the evolving needs of the organization.
Technical Expertise Approximately 70%
Detection Engineering
- Develop, test, implement, maintain, and optimize advanced security detection rules and logic.
- Develop SIEM use cases and detection content using technologies and frameworks such as YARA, Sigma, Splunk, Elastic, Microsoft Sentinel, or similar platforms.
- Analyze detection effectiveness and tune rules to improve threat visibility while reducing unnecessary alerts and false positives.
- Identify opportunities to strengthen Inmar's detection capabilities based on emerging threats, vulnerabilities, attack techniques, and lessons learned from security incidents.
Incident Detection and Response
- Lead or provide technical expertise for complex and high-priority security investigations.
- Analyze security alerts and events to determine scope, severity, business impact, and appropriate response.
- Coordinate containment, eradication, recovery, and other response activities in accordance with established incident response procedures.
- Maintain accurate and timely documentation of investigations, decisions, actions, findings, and outcomes.
- Escalate significant security incidents through established channels and support effective communication with appropriate stakeholders.
Threat Hunting
- Conduct proactive threat-hunting activities to identify potentially malicious activity that may not have been detected through existing security controls.
- Use threat intelligence, behavioral analytics, indicators of compromise, attack frameworks, and other available information to develop and execute threat-hunting hypotheses.
- Translate threat-hunting findings into improved detection capabilities, security controls, and response procedures where appropriate
Security Platform Optimization
- Partner with Cybersecurity Engineering and other technology teams to improve the configuration, performance, reliability, and effectiveness of security monitoring and detection platforms.
- Identify gaps in security visibility and recommend technical or process improvements.
- Participate in testing and implementation of enhancements to SOC tools and technologies.
Vulnerability and Security Risk Analysis
- Identify, assess, and communicate potential vulnerabilities and security weaknesses affecting systems, networks, applications, and related technology environments.
- Evaluate available security information and provide practical, risk-based recommendations for remediation or mitigation.
- Partner with appropriate technology and business stakeholders to support resolution of identified risks.
Technical Leadership and Mentorship
Team Collaboration and Mentorship
- Provide technical guidance and mentorship to SOC analysts.
- Support colleagues in developing investigation, incident response, threat detection, and security-tool capabilities.
- Serve as an escalation resource for complex security events and investigations.
- Encourage knowledge sharing, sound technical judgment, continuous learning, and effective problem solving across the team.
Knowledge Sharing
- Develop and deliver training, technical guidance, documentation, and other learning materials to strengthen SOC capabilities.
- Share lessons learned from incidents, threat-hunting activities, emerging threats, and security research.
- Help translate technical knowledge into repeatable practices that improve team effectiveness.
Process Improvement
- Develop, review, and improve SOC workflows, procedures, playbooks, and operational documentation.
- Identify opportunities to improve the consistency, quality, speed, and effectiveness of security operations.
- Support the implementation of industry practices appropriate to Inmar's environment and risk profile.
Operational Excellence Approximately 10%
Metrics and Reporting
- Develop and provide security reports, operational metrics, incident findings, trends, and recommendations to appropriate leadership and stakeholders.
- Identify patterns and insights from operational data that can improve security decisions and SOC effectiveness.
Change Management
- Implement changes to SOC technologies, configurations, workflows, and processes in accordance with established change-management and security procedures.
- Appropriately document changes, testing, approvals, and implementation outcomes.
Stakeholder Partnership
- Collaborate with Cybersecurity Engineering, Information Technology, business teams, and other internal stakeholders to support effective security operations.
- Communicate clearly during security incidents and ensure relevant stakeholders receive appropriate and timely information.
- Build productive working relationships across geographic, functional, and organizational boundaries.
Required Qualifications
Education and Experience
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field, or an equivalent combination of relevant education, professional certifications, and experience.
- Typically 10+ years of relevant qualified experience in security operations, cybersecurity analysis, incident response, detection engineering, or a related cybersecurity field.
- Demonstrated experience in Security Operations Center activities or a comparable security-monitoring and incident-response environment.
- Demonstrated experience developing and optimizing security detection logic using SIEM or related security platforms such as Splunk, Elastic, Microsoft Sentinel, or comparable technologies.
- Strong understanding of cybersecurity concepts and practices, including intrusion detection and prevention, security monitoring, malware analysis, threat intelligence, and incident response.
- Experience investigating security incidents and supporting or leading containment, eradication, recovery, and post-incident activities.
- Ability to analyze complex technical information, identify security risks, and develop practical recommendations.
- Effective written and verbal communication skills, including the ability to communicate technical information to different audiences.
- Ability to work effectively in a global, cross-functional environment.
Preferred Qualifications
- The following qualifications are preferred but are not required unless specifically identified as essential for the position.
- Detection Engineering
- Experience developing and maintaining advanced detection logic, including YARA, Sigma, SIEM rules, queries, correlation logic, or similar detection capabilities.
- Incident Response
- Demonstrated ability to lead or provide senior technical support for complex cybersecurity investigations and security incidents.
- Threat Hunting
- Experience conducting structured threat-hunting activities using threat intelligence, behavioral analytics, attack frameworks, and security telemetry.
- Cloud Security
- Experience monitoring or securing cloud environments such as Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), or comparable environments.
- Security Automation
- Experience automating security workflows using SOAR platforms, scripting, APIs, or programming languages such as Python.
- Professional Certifications
- Relevant cybersecurity certifications are advantageous but not required unless otherwise specified for the position.
Individual Competencies
- Integrity
- Acts responsibly and ethically, follows through on commitments, protects confidential and sensitive information, and builds trust through consistent actions and sound judgment.
- Teamwork and Collaboration
- Builds productive working relationships and works effectively with colleagues and stakeholders across teams, functions, and geographic locations to achieve shared objectives.
- Curiosity and Continuous Learning
- Actively seeks new knowledge, asks thoughtful questions, remains current on evolving cybersecurity threats and technologies, and uses new learning to improve individual and team effectiveness.
- Analytical and Critical Thinking
- Approaches complex problems logically and systematically,
evaluates available evidence, and distinguishes relevant information from assumptions.
- Communication
- Communicates information clearly and appropriately in written, verbal, and visual formats and adjusts communication based on the audience and situation.
- Problem Solving
- Gathers and evaluates relevant information, identifies potential solutions, considers risks and consequences, and uses sound judgment to resolve problems.
- Accountability
- Takes ownership of responsibilities, follows established processes and controls, escalates concerns appropriately, and delivers commitments with appropriate urgency and quality.
Work Schedule and Operational Requirements The Security Operations Center supports critical cybersecurity operations. Depending on the operating model assigned to this position, the role may require participation in rotational shifts, extended-hours coverage, weekend or public-holiday coverage, and/or an on-call schedule. Specific working hours, shift arrangements, rest periods, weekly days off, holiday coverage, and other scheduling requirements will be managed in accordance with applicable law, the employee's terms and conditions of employment, and Inmar policy.
Employees are expected to follow established incident escalation and availability procedures applicable to their assigned role and schedule.
Work Environment and Role Requirements
This is primarily a computer-based professional role. The employee regularly uses computers, security systems, communications tools, and other technology to monitor security environments, analyze information, investigate events, document findings, and communicate with colleagues and stakeholders.
The position may involve extended periods of computer-based work and, depending on operational requirements, participation in scheduled or on-call cybersecurity incident-response activities.
Inmar is committed to an inclusive and accessible workplace. Reasonable accommodation will be considered for persons with disabilities in accordance with applicable law and company policy.
The requirements described in this should be interpreted in relation to the essential responsibilities of the position and should not be used to unnecessarily exclude an otherwise qualified individual who can perform the role with reasonable accommodation, where applicable.
Inmar Leadership and Workplace Expectations
As an Inmar employee, you are expected to:
- Put clients first by understanding and responding to internal and external client needs and delivering high-quality outcomes.
- Treat colleagues, clients, and business partners with professionalism, courtesy, respect, and consideration.
- Build collaborative relationships and work effectively across teams, functions, cultures, and geographic locations.
- Take accountability for commitments and results and communicate early when risks, issues, or dependencies may affect delivery.
- Use sound judgment, facts, data, and appropriate expertise when making decisions.
- Remain curious, continue learning, and contribute to the development and effectiveness of others.
- Protect confidential, proprietary, personal, and security-sensitive information in accordance with applicable requirements and company policy.
- Follow applicable company policies, security requirements, workplace standards, and health and safety requirements.
- Contribute to a workplace that is professional, respectful, inclusive, and free from unlawful discrimination and harassment.
Equal Opportunity and Inclusion Inmar is committed to providing equal employment opportunities and maintaining a professional, respectful, and inclusive workplace.
Employment decisions are based on job-related qualifications, skills, experience, performance, capability, and legitimate business requirements, consistent with applicable law and Inmar policy.
Inmar does not tolerate unlawful discrimination in employment and is committed to meeting its obligations under applicable Indian law, including requirements relating to persons with disabilities and transgender persons.
Inmar will consider reasonable accommodation for persons with disabilities in accordance with applicable law and company policy.
Employees may raise concerns relating to discrimination, accessibility, accommodation, harassment, or other workplace matters through the grievance and reporting mechanisms established by Inmar.
Disclaimer
This summarizes the primary purpose, responsibilities, qualifications, and requirements of the position. It is not intended to describe every task or responsibility that may be assigned to the employee.
Responsibilities may evolve based on business, organizational, technology, security, or operational requirements, provided that changes are consistent with the nature and level of the role, applicable company policies, the employee's terms and conditions of employment, and applicable law.
Nothing in this is intended to modify statutory rights or obligations or the employee's applicable terms and conditions of employment.
Bottom of Form
📌 Sr.Soc Analyst - Lead/Manager (Hyderabad)
🏢 Inmar Technologies
📍 Hyderabad