Posted on: 10/10/2026
SOC Analyst - L1
We are looking for an experienced SOC Analyst - L1 to join a Cyber Fusion Centre and support 24x7 security monitoring and incident triage. The role involves working with SIEM, SOAR and EDR tools to investigate alerts, identify potential security incidents and escalate cases appropriately.
Location : Chennai
Your Future Employer : A leading global organization offering an opportunity to work in a structured cybersecurity environment with exposure to enterprise security operations and advanced security tools.
Responsibilities :
- Monitor real-time security alerts across SIEM, SOAR and EDR dashboards and perform first-level triage.
- Use Splunk to conduct basic SIEM queries and enrich alerts with relevant user, asset, network and timeline information.
- Log, categorize and escalate confirmed security incidents in accordance with defined incident management procedures.
- Follow established playbooks for phishing, malware, suspicious login and endpoint security alerts.
- Perform authorized Tier-1 containment actions, including endpoint isolation where applicable.
- Maintain accurate shift notes, ticket documentation and incident summaries.
- Ensure proper handover of open alerts and incidents between shifts.
- Escalate incidents outside the defined playbook scope to L2/L3 teams with complete evidence and timelines.
- Collaborate with security, threat intelligence, threat hunting and IT operations teams on security-related issues.
- Contribute observations and edge cases to runbooks and knowledge-base documentation.
Requirements :
- 1 - 3 years of hands-on experience in a Security Operations Centre, security monitoring or IT operations role with security exposure.
- Strong understanding of networking fundamentals including IP, DNS, ports and protocols.
- Knowledge of endpoint fundamentals across Windows/macOS environments.
- Familiarity with SIEM concepts and basic Splunk SPL/query construction.
- Foundational understanding of the MITRE ATT&CK framework and its application to alert triage.
- Experience working with ticketing systems such as ServiceNow, Jira or similar platforms.
- Strong written communication skills with the ability to prepare clear incident summaries and shift notes.
- Willingness to work in 24x7 rotational shifts, including nights, weekends and public holidays.
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology or a related field is preferred.
- Exposure to SOAR/EDR platforms such as Palo Alto Cortex XSOAR and Microsoft Defender for Endpoint will be an advantage.
What is in it for you :
- Opportunity to build your career in cybersecurity and SOC operations.
- Hands-on exposure to SIEM, SOAR and EDR technologies.
- Opportunity to work on real-time security monitoring and incident response.
- Exposure to enterprise-level security operations and cross-functional teams.
- Learning and development opportunities in the cybersecurity domain.
Did you find something suspicious?
Posted by
Shiwani Thakur
Recruitment Consultant at CRESCENDO GLOBAL LEADERSHIP HIRING INDIA PRIVATE L
Last Active: 10 Oct 2026
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1677772