HamburgerMenu
hirist

Lead SOC Analyst - Cyber Security

Sampoorna Computer People
7 - 10 Years
Multiple Locations

Posted on: 07/09/2026

Job Description

Core Responsibilities :

Incident Response & Investigation :

- Perform triage, investigation, containment, and remediation activities for complex and high-severity cybersecurity incidents.

- Act as a senior technical escalation point during incident handling, providing guidance and direction to analysts as required.

- Participate in incident bridges, contributing clear technical updates and investigative findings.

- Conduct forensic data collection and analysis across endpoints, network, cloud, and identity sources.

- Produce accurate and well-structured incident timelines, investigation notes, and post-incident summaries.

- Support post-incident reviews by contributing technical insights and lessons learned.

Detection & Threat Monitoring :

- Review and investigate alerts generated from SIEM, EDR, cloud security, and identity platforms.

- Support the tuning and refinement of detection rules to improve alert quality and reduce false positives.

- Conduct threat-hunting activities under defined hypotheses, using available telemetry and analytical techniques.

- Identify gaps in visibility or logging and raise these with senior analysts or engineering teams.

SOC Tooling & Automation Support :

- Use SOC tooling effectively to support investigations and response activities.

- Contribute ideas and feedback to improve SOC workflows, automation and playbooks.

- Assist with the validation and testing of changes to SOC tools and automated response processes.

- Highlight tooling issues or limitations that impact investigation effectiveness.

Governance, Process & Assurance Support :

- Support internal and external audit activities by providing investigation evidence and technical input when requested.

- Follow established SOC procedures and ensure investigations are documented accurately and consistently.

- Contribute to the maintenance of SOC documentation, playbooks and operational procedures.

- Participate in lessons-learned activities and contribute suggestions for process improvement.

Team & Stakeholder Interaction :

- Provide informal guidance and support to junior analysts during investigations, helping to improve analysis quality.

- Share technical knowledge and investigative techniques with peers through day-to-day collaboration.

- Communicate technical findings clearly to SOC leads and relevant stakeholders during incidents.

- Work collaboratively with Legal, Risk, Privacy, Crisis Management and Global SOC teams when required.

Operational Support :

- Support daily SOC monitoring activities during periods of increased workload or incident activity.

- Assist with escalation handling for complex alerts or investigations.

- Maintain a high standard of investigative quality and professional conduct during operational activity.

Required Skills & Experience :

- Experience working in a SOC, incident response or cybersecurity investigation role.

- Strong understanding of common attack techniques, threat actor behaviours, and investigative methodologies.

- Ability to analyse security alerts and logs across SIEM, EDR, cloud, identity and network security tools.

- Experience with scripting or automation (e.g. Python, PowerShell) is advantageous.

- Familiarity with frameworks such as MITRE ATT&CK, NIST CSF, or equivalent.

- Strong written and verbal communication skills, with the ability to explain technical findings clearly.

- Ability to work effectively under pressure during incident scenarios.

Preferred Qualifications :

- Relevant industry certifications such as CompTIA CySA+ or Microsoft Certified : Security Operations Analyst Associate (SC-200).

- Hands-on experience with EDR, SOAR, or forensic tooling.

- Experience participating in threat-hunting activities or security exercises.

- Exposure to tabletop or incident-response simulations.

- Certifications or demonstrated expertise in Microsoft security technologies related to Sentinel, Purview, or Microsoft Defender suites (e.g., Microsoft Certified : Information Protection Administrator Associate (SC-400), Microsoft Certified : Azure Security Engineer Associate (AZ-500)).

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...