Description :
We are looking for a skilled and proactive SOC Analyst with 2+ years of hands-on experience in Security Operations, Incident Detection, Threat Monitoring, and Security Incident Response. The candidate should have strong knowledge of SIEM, EDR, Security Automation, SOAR, Threat Intelligence, Email Security, Log Analysis, Cloud Security, and Security Monitoring processes.
Key Responsibilities :
- Monitor and investigate security alerts from SIEM, EDR, Firewall, IDS/IPS, WAF, Email Security, and Cloud Security tools.
- Perform incident analysis, threat detection, log analysis, and escalation handling.
- Handle phishing, malware, brute force, ransomware, and suspicious activity investigations.
- Create, tune, and optimize SIEM detection rules, correlation rules, and use cases.
- Work on SOC automation and SOAR playbook development for incident response and alert enrichment.
- Perform threat hunting and IOC analysis using MITRE ATT&CK framework.
- Monitor AWS cloud security events and vulnerabilities.
- Coordinate with infrastructure/application teams for remediation activities.
Required Skills :
- Hands-on experience with SIEM tools like Wazuh, Splunk, IBM QRadar, Microsoft Sentinel
- Experience with SOAR platforms and security automation workflows
- Knowledge of SIEM rule creation, correlation logic, alert tuning, and dashboard creation
- Understanding of EDR, Threat Hunting, Incident Response, and MITRE ATT&CK
- Basic Knowledge of IDS/IPS, Email Security, and network security
- Knowledge of AWS Security services like CloudTrail, cloudwatch, Security Hub, EC2, VPC, Trusted advisor etc
- Vulnerability management experience using Nessus or Qualys
- Basic scripting/automation knowledge in Python, PowerShell, or Bash preferred