SOC Analyst

Mumbai · Hybrid Full-time 5-7 years B.Tech/Degree (CSE, IT, related) Direct Client hiring Posted 3 months ago💰 Not disclosed
Apply now

Must Have Skills

SIME (Splunk/ SumoLogic/ Qradar/ Sentinel) and EDR (Crowdstrike/ CarbonBlack/ SentinelOne)Cybersecurity OperationsSIEM Monitoring & Log AnalysisThreat HuntingIncident ResponseSecurity AutomationEndpoint Detection & Response (EDR)Cloud Security MonitoringSecurity Event InvestigationSOAR, Automation, Malware Analysis, Threat Intelligence

Preferred Skills

SIME (Splunk/ SumoLogic/ Qradar/ Sentinel) and EDR (Crowdstrike/ CarbonBlack/ SentinelOne)Cybersecurity OperationsSIEM Monitoring & Log AnalysisThreat HuntingIncident ResponseSecurity AutomationEndpoint Detection & Response (EDR)Cloud Security MonitoringSecurity Event InvestigationSOAR, Automation, Malware Analysis, Threat Intelligence

About the Opportunity

We are hiring on behalf of a globally recognized technology and digital transformation organization seeking a highly skilled SOC Analyst to join its Cybersecurity Operations team. The ideal candidate will play a critical role in strengthening enterprise security posture through proactive threat detection, incident response, threat hunting, and security operations automation.

Key Responsibilities

Security Operations & Monitoring

  1. Perform initial and secondary triage of security alerts generated through internal monitoring tools and external SOC/MSSP partners.
  2. Monitor, analyze, and investigate cyber threats across endpoint, cloud, identity, network, and mobile environments.
  3. Detect, identify, and respond to cyber incidents in alignment with organizational security policies and procedures.
  4. Participate in a 24x7 SOC operational environment and support escalation handling when required.

Threat Hunting & Incident Response

  1. Conduct proactive threat hunting activities using SIEM, EDR, and intelligence-driven methodologies.
  2. Investigate emerging threats, malware trends, attacker TTPs, and evolving threat landscapes.
  3. Support end-to-end incident response activities including investigation, containment, remediation, recovery, and post-incident documentation.
  4. Drive incident response automation workflows and contribute to continuous process improvement initiatives.

Cloud & Endpoint Security

  1. Work with CSPM tools such as Wiz or similar cloud security platforms to strengthen cloud security posture.
  2. Monitor and investigate endpoint security events using EDR tools like CrowdStrike, SentinelOne, Carbon Black, or equivalent.
  3. Collaborate with platform engineering and security engineering teams to improve security tool effectiveness and operational workflows.

Security Engineering & Automation

  1. Author detection rules, correlation searches, dashboards, and investigation content using SIEM query languages.
  2. Develop scripts for event enrichment, automation, and investigation using Python, PowerShell, SQL, or similar technologies.
  3. Assist in validating security controls and improving detection coverage across enterprise systems.
  4. Support SOAR platform integrations and automation initiatives wherever applicable.

Documentation & Collaboration

  1. Maintain detailed documentation for incident lifecycle management, escalation procedures, and operational runbooks.
  2. Coordinate effectively with cybersecurity teams, infrastructure teams, application teams, and external security partners.
  3. Participate in tabletop exercises, postmortems, and continuous improvement reviews with measurable security benchmarks.

Required Skills & Technical Expertise

Core Skills

  1. Cybersecurity Operations
  2. SIEM Monitoring & Log Analysis
  3. Threat Hunting
  4. Incident Response
  5. Security Automation
  6. Endpoint Detection & Response (EDR)
  7. Cloud Security Monitoring
  8. Security Event Investigation

SIEM Tools

Experience with one or more:

  1. Splunk
  2. Microsoft Sentinel
  3. QRadar
  4. Sumo Logic
  5. Other enterprise SIEM platforms

EDR / Security Tools

Experience with:

  1. CrowdStrike
  2. SentinelOne
  3. Carbon Black
  4. Other endpoint security platforms

Cloud Security

  1. Experience with Wiz or equivalent CSPM solutions
  2. Understanding of cloud attack vectors and cloud security monitoring

Scripting & Query Languages

  1. SQL
  2. Python
  3. PowerShell

Additional Preferred Skills

  1. SOAR platforms
  2. Security control validation
  3. Threat intelligence analysis
  4. Malware analysis fundamentals

Qualifications

Education

  1. Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field.

Preferred Certifications

Any of the following certifications would be an added advantage:

  1. CISSP
  2. CISM
  3. CEH
  4. GCIH
  5. GCIA
  6. GSOC

Experience Required

  1. 4–8 years of experience in:
  2. Enterprise Cybersecurity
  3. SOC Operations
  4. Security Consulting Services
  5. Managed Security Services
  6. Incident Response & Threat Detection
  7. Experience working within highly dynamic and operationally intensive security environments.

Apply to this job

Required — upload a file or paste the text