Posted on: 08/09/2026
Role Overview :
This role is a senior Information Security position (7+ years total, 5+ relevant) focused on L2 Security Operations within Infrastructure Security Services.
Key technical areas include SIEM (rule tuning, log source integration, correlation optimization), Vulnerability Management (CVE analysis, false positive/negative triage, custom scripting), Cortex XDR (threat hunting, policy configuration, incident detection), and PAM (privileged account/session management, compliance reporting across Windows/UNIX/LDAP/Databases).
Core responsibilities span incident response, threat protection, identity & access management, and vulnerability management end-to-end.
The role also carries leadership duties - leading complex incident investigations/forensics, mentoring L1/L2 analysts, and collaborating with security engineers and IT teams.
Additional expectations include staying current on threat intelligence/trends, driving process improvements, and maintaining thorough incident documentation.
Company Overview :
Zelis is one of the leading healthcare technology Product organizations with $1.4 Billion revenue with year-on-year growth of 22% and client retention rate of 120%.
We offer wide range of innovative solutions to the healthcare payers, providers, and consumers.
Our services include network analytics, payment integrity and optimization, provider credentialing, and provider engagement.
Zelis is an US based Software Product development organization founded in 1995 with a headcount 2400+ talented professionals working in 7 offices in US and 1 global capacity center located in Hyderabad, India.
Position : L2 SOC Analyst
Location : Hyderabad
Work Mode : Work from Office - Rotational Shifts
Overview :
As a L2 SOC Analyst at Zelis, you will play a critical role in maintaining the security of our clients' systems and data.
You will be responsible for monitoring, analyzing, and responding to security alerts and incidents, ensuring that potential threats are identified and escalated for mitigation in a timely manner.
Primary Responsibilities :
- Undergraduate degree or equivalent experience.
- Minimum 7 plus overall experience out of minimum 5 years of relevant experience in Information security domain.
- Proven expertise of Security Operations (L2/ L1) in Infrastructure Security Services domains.
- Ability to resolve issues pertaining to security solutions implemented at client locations.
- Working experience on incident response, threat protections, SecOps, identity & Access management & vulnerability management.
Technical Skills :
1. SIEM Skills :
- Create, modify, and tune the SIEM rules to adjust the specifications of alerts and incidents.
- Knowledge Integrating various log sources like Windows, Linux, Pala alto firewall, AWS, Etc.
- To provide continual correlation rule tuning, incident classification and prioritization recommendations.
- Report query adjustments, and various other SIEM configuration activities.
- Ability to fully optimize the SIEM system capabilities as well as the audit and logging features of the event log sources.
- Work closely with the other teams related to Network, Device, Policy, connectivity issues etc.
- Identify new opportunities/threats in the network to improve the security of the network.
- Monitor and administer enterprise log correlation (SIEM).
- Select, design, implement and manage security measures to reduce the risk of loss.
2. VM Skills :
- Collecting, analyzing, interpreting, evaluating, and integrating vulnerability data from multiple sources to update existing product.
- Vulnerability/exploit research and creating signatures for the same.
- Handle Customer escalations, to identify False-Positive & False-Negative.
- Actively investigate the latest in security vulnerabilities, advisories, incidents, and provide insights (sources like, Microsoft, Oracle, etc).
- Troubleshooting security vulnerability issues/ gaps that arise.
- Vulnerability data discovery and validation (Data efficacy & Accuracy).
- Develop, test and modify custom scripts for vulnerability content.
- Manually/Automate analyzing new CVE information published.
3. XDR Skills :
- Monitor and analyzing Threat hunting, Deep investing on Cortex XDR Alerts, Detection, Incidents.
- Troubleshoot and Configure Prevention Policies, Custom IOA Rule Groups, Detections Management, Exclusions, IOC Management, Firewall Policies, Firewall Rule Groups, USB Device Policies, Response Policies, Response Scripts & Files, Containment Policy, Sensor Update Policies.
- Should be able to check and utilize all Vulnerability feature in spotlight.
4. PAM Skills :
- Perform daily tasks that include reconciliation of servers, daily health check of the PAM servers, run daily compliance reports, etc.
- Manage Privileged Session Management and associated policies.
- Create and manage Platforms, Policies and Safes for Privileged ID's.
- Responsible for Privileged User account administration for various platforms including Windows, UNIX, LDAP, Databases.
- Manage Service Accounts, Non-Production Accounts, Test Accounts within the vaults.
- Develop and maintain documentation for security systems and procedures.
- Reporting and metrics.
Management Skills :
- Analyze, investigate, lead and coordinate responses to complex, advanced security events and alerts, perform forensic analysis to understand extent of compromise by using respective tools.
- Monitor, analyse security threats, vulnerabilities and trends by utilize threat intelligence to enhance detection and response capabilities.
- Provide guidance, conduct trainings and support to level 1 and 2 SOC analysts.
- Collaborate, Assist with security engineers to deploy, develop, implement and manage security tools and architecture.
- Work closely with IT and security teams to coordinate efforts.
- Identify opportunities for improving security processes and technology.
- Stay upto date on cybersecurity trends and threats.
- Documenting security incidents, responses and related information in accordance with procedures.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1669496