Posted on: 04/08/2026
Role & Responsibilities :
- Monitor and analyze security alerts from SIEM, EDR, XDR, IDS/IPS, firewalls, and other security monitoring tools.
- Perform Level 2/Level 3 SOC operations including alert triage, investigation, containment, and escalation.
- Conduct in-depth analysis of security incidents, suspicious activities, malware alerts, phishing attempts, and potential breaches.
- Perform threat hunting activities using threat intelligence, MITRE ATT&CK techniques, and indicators of compromise (IOCs).
- Investigate logs from various sources including endpoints, servers, network devices, cloud platforms, and applications.
- Create detailed incident reports, root cause analysis (RCA), and recommendations for preventing future incidents.
- Manage and respond to security incidents according to defined incident response processes and SLAs.
- Correlate events across multiple security platforms to identify advanced threats and attack patterns.
- Develop and improve detection rules, correlation searches, use cases, and security monitoring dashboards.
- Tune SIEM alerts to reduce false positives and improve detection accuracy.
- Perform malware analysis and suspicious file investigations when required.
- Provide mentorship and technical guidance to junior SOC analysts.
- Participate in 24x7 SOC operations and rotational shifts when required.
Preferred Candidate Profile :
- Bachelors degree in Computer Science, Information Security, Cybersecurity, or related field.
- 5 to 10 years of experience in Security Operations Center (SOC) environments.
- Strong experience handling L2/L3 security incidents and investigations.
- Hands-on experience with SIEM platforms such as:
1. Splunk Enterprise Security
2. Microsoft Sentinel
3. IBM QRadar
4. ArcSight
5. LogRhythm
- Experience with EDR/XDR solutions such as:
1. Microsoft Defender for Endpoint
2. CrowdStrike Falcon
3. SentinelOne
4. Palo Alto Cortex XDR
- Strong understanding of:
1. Network security concepts (TCP/IP, DNS, HTTP/HTTPS, VPN, firewalls)
2. Windows and Linux operating systems
3. Active Directory security
4. Cloud security fundamentals (Azure/AWS/GCP)
5. Threat intelligence and IOC analysis
6. MITRE ATT&CK framework
7. Incident response lifecycle
- Ability to perform:
1. Threat hunting
2. Log correlation
3. Malware investigation
4. Phishing analysis
5. Digital forensics basics
- Knowledge of security frameworks and standards:
1. ISO 27001
2. NIST Cybersecurity Framework
3. CIS Controls
4. PCI-DSS (preferred)
- Relevant certifications preferred:
1. CISSP
2. CISM
3. CEH
4. GIAC (GCIH/GCIA/GCFA)
5. OSCP
6. CompTIA Security+
7. Splunk Certified Cybersecurity Analyst
8. Microsoft Security certifications
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1660409