HamburgerMenu
hirist

Ntechworkforce - Senior Security Operations Center Analyst

nTech Workforce
4 - 6 Years
Hyderabad

Posted on: 25/08/2026

Job Description

Role : SOC Analyst

No. of Positions : 1

Contract Duration : 6 Months-12 Months

Location : Hyderabad

Mode of Work : Onsite

Shift Timings : Afternoon Shift

Job Description :

Role is 100% in Hyderabad office.

Overview :

The Senior SOC Analyst serves as the highest-level escalation point within the Security Operations Centre, specializing in complex investigations, advanced detection engineering support, and end-to-end incident response leadership. This role requires a high degree of technical depth, cross-functional collaboration, and the ability to guide SOC improvements through automation, AI-assisted workflows, and mentorship of junior analysts. Senior analysts shape SOC maturity through expert-level case handling, content refinement, proactive threat hunting support, and ongoing leadership in improving SOC processes, tooling, and response efficiency.

Key Responsibilities :

Advanced Investigation, Incident Handling & Incident Response :

- Lead complex, high-severity investigations across endpoint, network, cloud, and identity telemetry.

- Perform root cause analysis and reconstruct incident timelines using aligned MITRE ATT&CK mapping.

- Serve as the primary technical liaison during escalated incidents, delivering clear findings and remediation steps to internal leadership and clients.

- Drive the creation of After-Action Reports (AARs) and lessons learned to improve tooling, detections, and workflow performance.

Detection Engineering & Content Support :

- Identify detection gaps and collaborate with Detection Engineering to develop, refine, and tune SIEM and EDR rules.

- Validate new detections before SOC deployment and provide measurable feedback based on production telemetry.

SOAR Automation & Workflow Optimization :

- Leverage SOAR platforms to automate enrichment, triage, and response actions.

- Identify repetitive patterns ideal for automation and propose workflow enhancements to reduce MTTR.

- Validate automation logic prior to production rollout and ensure alignment with SOC escalation policies.

- Collaborate with engineering teams to incorporate additional enrichment sources, threat intel lookups, and AI-driven analysis steps.

AI, Machine Learning & Prompt Engineering :

- Utilize AI copilots, enrichment agents, and LLM-based analysis tools to support case triage, enrichment, and investigation.

- Develop, optimize, and maintain prompt templates for SOC use cases (enrichment summaries, detection validation, log interpretation, hypothesis generation).

- Evaluate the accuracy and reliability of AI-generated outputs and implement QA steps to avoid hallucinations or misleading results.

- Identify opportunities to integrate AI agents into detection, triage, and response workflowsimproving analyst speed and consistency.

- Provide feedback to engineering teams on model behavior, content gaps, and automation integration opportunities.

Threat Hunting & Proactive Analysis :

- Support hypothesis-driven and intelligence-led hunts by validating findings, artifacts, and suspicious patterns.

- Recommend new hunts based on emerging TTPs, anomalous case trends, or telemetry gaps discovered during investigations.

- Ensure hunt findings translate into new detections, enhanced content, or instrumentation improvements.

Leadership, Mentoring & Team Development :

- Mentor junior analysts on investigation techniques, tooling proficiency, case documentation, and proper analytical depth.

- Conduct quality reviews of Tier 1/2 case handling and provide constructive feedback.

- Contribute to training guides, runbooks, knowledge bases, and onboarding materials.

- Lead technical briefings, internal workshops, and knowledge-sharing sessions across SOC teams.

Reporting & Continuous Improvement :

- Produce clear, concise, and accurate technical reports, incident summaries, and executive-friendly communications.

- Identify inefficiencies and propose enhancements in monitoring, detection logic, processes, and analyst training.

Required Qualifications :

- 4-6 years of experience in cybersecurity, especially in SOC, threat hunting, detection engineering, or incident response roles.

- Strong understanding of threat hunting concepts and methodologies.

- Familiarity with EDR tools, SIEM platforms, and log analysis.

- Basic proficiency in writing detection queries or scripts (e.g., KQL, Sigma, PowerShell).

- Strong analytical thinking and investigative skills.

Preferred Qualifications :

- Certifications such as GCIH, GCFA, GCDA, or similar.

- Experience with Elastic, Splunk, or other search-based platforms.

- Knowledge of the MITRE ATT&CK framework.

- Exposure to scripting languages for automation and enrichment.

Key Attributes :

- Curious and detail-oriented with a passion for proactive defence.

- Able to work independently or collaboratively in high-paced environments.

- Strong written and verbal communication skills.

- Bachelors degree in Cybersecurity, Information Technology, Computer Science, or a related field.

This role provides a hands-on opportunity to engage in proactive threat detection and response activities and contribute directly to the maturity and effectiveness of the SOCs security posture.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...