SOC Analyst
Mumbai · Hybrid Full-time 5-7 years B.Tech/Degree (CSE, IT, related) Direct Client hiring Posted 3 months ago💰 Not disclosed
Must Have Skills
SIME (Splunk/ SumoLogic/ Qradar/ Sentinel) and EDR (Crowdstrike/ CarbonBlack/ SentinelOne)Cybersecurity OperationsSIEM Monitoring & Log AnalysisThreat HuntingIncident ResponseSecurity AutomationEndpoint Detection & Response (EDR)Cloud Security MonitoringSecurity Event InvestigationSOAR, Automation, Malware Analysis, Threat Intelligence
Preferred Skills
SIME (Splunk/ SumoLogic/ Qradar/ Sentinel) and EDR (Crowdstrike/ CarbonBlack/ SentinelOne)Cybersecurity OperationsSIEM Monitoring & Log AnalysisThreat HuntingIncident ResponseSecurity AutomationEndpoint Detection & Response (EDR)Cloud Security MonitoringSecurity Event InvestigationSOAR, Automation, Malware Analysis, Threat Intelligence
About the Opportunity
We are hiring on behalf of a globally recognized technology and digital transformation organization seeking a highly skilled SOC Analyst to join its Cybersecurity Operations team. The ideal candidate will play a critical role in strengthening enterprise security posture through proactive threat detection, incident response, threat hunting, and security operations automation.
Key Responsibilities
Security Operations & Monitoring
- Perform initial and secondary triage of security alerts generated through internal monitoring tools and external SOC/MSSP partners.
- Monitor, analyze, and investigate cyber threats across endpoint, cloud, identity, network, and mobile environments.
- Detect, identify, and respond to cyber incidents in alignment with organizational security policies and procedures.
- Participate in a 24x7 SOC operational environment and support escalation handling when required.
Threat Hunting & Incident Response
- Conduct proactive threat hunting activities using SIEM, EDR, and intelligence-driven methodologies.
- Investigate emerging threats, malware trends, attacker TTPs, and evolving threat landscapes.
- Support end-to-end incident response activities including investigation, containment, remediation, recovery, and post-incident documentation.
- Drive incident response automation workflows and contribute to continuous process improvement initiatives.
Cloud & Endpoint Security
- Work with CSPM tools such as Wiz or similar cloud security platforms to strengthen cloud security posture.
- Monitor and investigate endpoint security events using EDR tools like CrowdStrike, SentinelOne, Carbon Black, or equivalent.
- Collaborate with platform engineering and security engineering teams to improve security tool effectiveness and operational workflows.
Security Engineering & Automation
- Author detection rules, correlation searches, dashboards, and investigation content using SIEM query languages.
- Develop scripts for event enrichment, automation, and investigation using Python, PowerShell, SQL, or similar technologies.
- Assist in validating security controls and improving detection coverage across enterprise systems.
- Support SOAR platform integrations and automation initiatives wherever applicable.
Documentation & Collaboration
- Maintain detailed documentation for incident lifecycle management, escalation procedures, and operational runbooks.
- Coordinate effectively with cybersecurity teams, infrastructure teams, application teams, and external security partners.
- Participate in tabletop exercises, postmortems, and continuous improvement reviews with measurable security benchmarks.
Required Skills & Technical Expertise
Core Skills
- Cybersecurity Operations
- SIEM Monitoring & Log Analysis
- Threat Hunting
- Incident Response
- Security Automation
- Endpoint Detection & Response (EDR)
- Cloud Security Monitoring
- Security Event Investigation
SIEM Tools
Experience with one or more:
- Splunk
- Microsoft Sentinel
- QRadar
- Sumo Logic
- Other enterprise SIEM platforms
EDR / Security Tools
Experience with:
- CrowdStrike
- SentinelOne
- Carbon Black
- Other endpoint security platforms
Cloud Security
- Experience with Wiz or equivalent CSPM solutions
- Understanding of cloud attack vectors and cloud security monitoring
Scripting & Query Languages
- SQL
- Python
- PowerShell
Additional Preferred Skills
- SOAR platforms
- Security control validation
- Threat intelligence analysis
- Malware analysis fundamentals
Qualifications
Education
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field.
Preferred Certifications
Any of the following certifications would be an added advantage:
- CISSP
- CISM
- CEH
- GCIH
- GCIA
- GSOC
Experience Required
- 4–8 years of experience in:
- Enterprise Cybersecurity
- SOC Operations
- Security Consulting Services
- Managed Security Services
- Incident Response & Threat Detection
- Experience working within highly dynamic and operationally intensive security environments.
Apply to this job
Required — upload a file or paste the text
