07 Oct
|
Celito Tech
|
India
Job Title: Senior SOC Analyst
Reports To: Manager, Cybersecurity Operations
Day-to-Day Direction: Lead SOC Analyst
Escalates To: Lead SOC Analyst
Receives Escalations From: SOC Analysts
Employment Type: Full time
Workplace Type: Remote
Schedule: Assigned shift rotation, including nights and weekends as scheduled
Operating Framework: Documented SOC incident response procedures The Celito Team The Celito Team architects the buildout of simplified, integrated, and compliant technology stacks. With both consulting and products, our expertise can help our customers save time and money as they move from strategic Clinical & Quality management all the way to widespread and profitable commercialization.
Job Overview
As a Senior SOC Analyst, you will serve as the technical resolution point for Celito’s Security Operations Center. You will complete the work escalated from SOC Analysts, taking ownership of the record through to resolution rather than returning it for rework. You will act as the first quality gate on investigations and incident reports, performing technical review before that work reaches the Lead SOC Analyst and the SOC Manager.
You will serve as the Lead SOC Analyst’s technical delegate during Incident Response engagements and in the Lead’s absence, and you will support the SOC Analyst tier with real-time investigative guidance, documented quality feedback, and knowledge transfer. You will also draft and maintain the runbooks, triage playbooks, SOAR automation logic, and detection tuning recommendations that keep response consistent across Celito’s client environments.
Responsibilities and Duties
- Complete tickets and investigations escalated from SOC Analysts, taking ownership through to resolution.
- Handle escalated Incident Response investigations where requested by the Lead SOC Analyst, including multi-host, multi-identity, and cross-tenant scope.
- Perform advanced analysis beyond standard triage, including timeline reconstruction, lateral movement and persistence analysis, log correlation across ingestion pipelines,
and blast radius scoping.
- Determine whether an escalated event is confirmed malicious or remains suspicious, and record the basis for that determination, which governs whether containment precedes or follows client notification and approval procedures.
- Escalate to the Lead SOC Analyst where the client’s approved response authorization is ambiguous or cannot be confirmed, or where the incident requires client leadership or Celito management involvement.
- Serve as the named first escalation receiver for all SOC Analysts on shift and respond within the agreed escalation target.
- Provide real-time investigative guidance so the Analyst retains ownership where the escalation reflects a knowledge gap rather than a scope or authority gap.
- Assume client communication duty when a SOC Analyst is committed to an active investigation, so that one responder remains on the investigation while the other handles calls, coordinating the handoff with the Lead SOC Analyst.
- Support end-user recovery assistance where volume or complexity exceeds what the Analyst can carry alongside the investigation.
- Perform first-pass qualitative review of SOC Analyst tickets against the SOC quality criteria, covering classification accuracy, severity assignment, investigative completeness, containment correctness, and documentation quality.
- Perform technical review of incident reports before they reach the Lead SOC Analyst and the SOC Manager.
- Provide documented feedback to the Analyst, verify remediation, and escalate recurring patterns rather than individual findings to the Lead SOC Analyst.
- Draft, test, and maintain Incident Response runbooks,
triage playbooks, and SOAR automation logic for approval by the Lead SOC Analyst.
- Own detection tuning recommendations arising from false positive analysis and submit them for approval before deployment.
- Contribute to revisions of documented SOC incident response procedures and deliver knowledge transfer to the SOC Analyst tier, including shift briefings and onboarding.
- Serve as secondary on-call for Incident Response escalations, act as shift lead in the Lead SOC Analyst’s absence, and report any period in which defined minimum shift coverage cannot be maintained.
- Work assigned shift rotations, including nights and weekends as scheduled, to meet the operational demands of Celito’s clients.
- Perform other duties as assigned.
Qualifications
- Three to six years in security operations, with demonstrated ownership of full incident lifecycles.
- Advanced proficiency in endpoint forensics, identity compromise investigation, cloud and SaaS audit log analysis, and detection engineering fundamentals.
- Demonstrated ability to build and maintain SOAR workflows and to write queries and scripts supporting investigation at scale.
- Demonstrated ability to determine whether an escalated event is confirmed malicious or remains suspicious and to document the basis for that determination in client-facing incident records.
- Excellent organizational, communication and customer service skills with active-listening skills.
- Preferred Certifications: SANS GCIH, CompTIA CySA+, Crowdstrike CCFA or alternative vendor equivalent.
- Experienced with implementing, managing, and supporting the following technology platforms: (or equivalent expertise)
- Endpoint Detection & Response: CrowdStrike Falcon, including NG-SIEM, Real Time Response, and Fusion SOAR
- Identity Management & SSO: Microsoft Entra ID, Okta
- Email/Productivity & Cloud: Microsoft 365, Microsoft Defender
- SIEM/XDR: at least one additional SIEM or XDR platform beyond CrowdStrike NG-SIEM
📌 Senior SOC Analyst (India)
🏢 Celito Tech
📍 India