08 Oct
|
Sampoorna Consultants
|
Bengaluru
08 Oct
Sampoorna Consultants
Bengaluru
Lead SOC Analyst - AM - BLR / GGN - J50820
Role & responsibilities
Core Responsibilities
Incident Response & Investigation
• Perform triage, investigation, containment, and remediation activities for complex and high-severity cybersecurity incidents.
• Act as a senior technical escalation point during incident handling, providing guidance and direction to analysts as required.
• Participate in incident bridges, contributing clear technical updates and investigative findings.
• Conduct forensic data collection and analysis across endpoints, network, cloud, and identity sources.
• Produce accurate and well-structured incident timelines, investigation notes, and post-incident summaries.
• Support post-incident reviews by contributing technical insights and lessons learned.
Detection & Threat Monitoring
• Review and investigate alerts generated from SIEM, EDR, cloud security, and identity platforms.
• Support the tuning and refinement of detection rules to improve alert quality and reduce false positives.
• Conduct threat-hunting activities under defined hypotheses, using available telemetry and analytical techniques.
• Identify gaps in visibility or logging and raise these with senior analysts or engineering teams.
SOC Tooling & Automation Support
• Use SOC tooling effectively to support investigations and response activities.
• Contribute ideas and feedback to improve SOC workflows, automation and playbooks.
• Assist with the validation and testing of changes to SOC tools and automated response processes.
• Highlight tooling issues or limitations that impact investigation effectiveness.
Governance, Process & Assurance Support
• Support internal and external audit activities by providing investigation evidence and technical input when requested.
• Follow established SOC procedures and ensure investigations are documented accurately and consistently.
• Contribute to the maintenance of SOC documentation, playbooks and operational procedures.
• Participate in lessons-learned activities and contribute suggestions for process improvement.
Team & Stakeholder Interaction
• Provide informal guidance and support to junior analysts during investigations, helping to improve analysis quality.
• Share technical knowledge and investigative techniques with peers through day-to-day collaboration.
• Communicate technical findings clearly to SOC leads and relevant stakeholders during incidents.
• Work collaboratively with Legal, Risk, Privacy, Crisis Management and Global SOC teams when required.
Operational Support
• Support daily SOC monitoring activities during periods of increased workload or incident activity.
• Assist with escalation handling for complex alerts or investigations.
• Maintain a high standard of investigative quality and qualified conduct during operational activity.
Required Skills & Experience
• Experience working in a SOC, incident response or cybersecurity investigation role.
• Strong understanding of common attack techniques, threat actor behaviours, and investigative methodologies.
• Ability to analyse security alerts and logs across SIEM, EDR, cloud, identity and network security tools.
• Experience with scripting or automation (e.g. Python, PowerShell) is advantageous.
• Familiarity with frameworks such as MITRE ATT&CK;, NIST CSF, or equivalent.
• Strong written and verbal communication skills, with the ability to explain technical findings clearly.
• Ability to work effectively under pressure during incident scenarios.
Preferred Qualifications
• Relevant industry certifications such as CompTIA CySA+ or Microsoft Certified:
• Security Operations Analyst Associate (SC-200).
• Hands-on experience with EDR, SOAR, or forensic tooling.
• Experience participating in threat-hunting activities or security exercises.
• Exposure to tabletop or incident-response simulations.
• Certifications or demonstrated expertise in Microsoft security technologies related to Sentinel, Purview, or Microsoft Defender suites (e.g., Microsoft Certified: Information Protection Administrator Associate (SC-400), Microsoft Certified: Azure Security Engineer Associate (AZ-500)).
📌 Lead SOC Analyst (Bengaluru)
🏢 Sampoorna Consultants
📍 Bengaluru