
SOC Analyst
- Pune, Maharashtra
- Permanent
- Full-time
- Monitor and triage alerts from SIEM platforms including Elastic Stack, correlating data from Zscaler, Defender for Endpoint, CrowdStrike Falcon, and other security tools.
- Investigate suspicious activity and escalate confirmed incidents with detailed impact assessments.
- Support incident response lifecycle—including containment, eradication, and recovery—according to defined playbooks.
- Collaborate with senior analysts and threat intelligence teams to conduct in-depth investigations and recommend mitigations.
- Perform log analysis, packet capture review, and behavioral analytics to uncover advanced threats.
- Conduct proactive threat hunting using data across various telemetry sources (e.g., endpoint, network, cloud).
- Document investigation steps, findings, and resolution actions for audit and knowledge base purposes.
- Continuously tune SIEM rules, detection logic, and alert thresholds to reduce false positives and increase fidelity.
- Provide audit and compliance support during security assessments and regulatory evaluations.
- Participate in weekly SOC reviews and post-incident reviews to improve detection and response capabilities.
- Stay updated with the latest threat intel, CVEs, TTPs (MITRE ATT&CK), and industry best practices.
- Bachelor’s degree in computer science, Cybersecurity, Information Technology, or related field.
- 2–3 years of hands-on experience in a SOC or cybersecurity role, ideally in a 24x7 monitoring environment.
- Solid knowledge of:
- Endpoint detection tools (CrowdStrike Falcon, Defender for Endpoint)
- Network and cloud security solutions (Zscaler Internet Access/ZPA)
- Open-source and commercial SIEM tools (preferably Elastic/ELK).
- Understanding of network protocols, log formats, and Windows/Linux/macOS security.
- Familiarity with MITRE ATT&CK, CVE/CVSS scoring, and vulnerability management principles.
- Strong communication and incident documentation skills.
- Willingness to work in rotational shifts for continuous 24x7 SOC coverage.
- Preferred certifications: CompTIA Security+, Microsoft SC-200, Elastic Certified Analyst, CrowdStrike Certified Falcon Responder, or similar.