Back to jobs

Senior Security Operations Center Analyst - Threat Hunting

Good CoIndiaAdded 1d ago
SOC Analyst
Full-time
Apply on company siteCraft my tailored resume free

Free to start · No card

Job description

Role & Responsibilities : - Monitor and analyze security alerts from SIEM, EDR, XDR, IDS/IPS, firewalls, and other security monitoring tools. - Perform Level 2/Level 3 SOC operations including alert triage, investigation, containment, and escalation. - Conduct in-depth analysis of security incidents, suspicious activities, malware alerts, phishing attempts, and potential breaches. - Perform threat hunting activities using threat intelligence, MITRE ATT&CK techniques, and indicators of compromise (IOCs). - Investigate logs from various sources including endpoints, servers, network devices, cloud platforms, and applications. - Create detailed incident reports, root cause analysis (RCA), and recommendations for preventing future incidents. - Manage and respond to security incidents according to defined incident response processes and SLAs. - Correlate events across multiple security platforms to identify advanced threats and attack patterns. - Develop and improve detection rules, correlation searches, use cases, and security monitoring dashboards. - Tune SIEM alerts to reduce false positives and improve detection accuracy. - Perform malware analysis and suspicious file investigations when required. - Provide mentorship and technical guidance to junior SOC analysts. - Participate in 24x7 SOC operations and rotational shifts when required. Preferred Candidate Profile : - Bachelors degree in Computer Science, Information Security, Cybersecurity, or related field. - 5 to 10 years of experience in Security Operations Center (SOC) environments. - Strong experience handling L2/L3 security incidents and investigations. - Hands-on experience with SIEM platforms such as: 1. Splunk Enterprise Security 2. Microsoft Sentinel 3. IBM QRadar 4. ArcSight 5. LogRhythm - Experience with EDR/XDR solutions such as: 1. Microsoft Defender for Endpoint 2. CrowdStrike Falcon 3. SentinelOne 4. Palo Alto Cortex XDR - Strong understanding of: 1. Network security concepts (TCP/IP, DNS, HTTP/HTTPS, VPN, firewalls) 2. Windows and Linux operating systems 3. Active Directory security 4. Cloud security fundamentals (Azure/AWS/GCP) 5. Threat intelligence and IOC analysis 6. MITRE ATT&CK framework 7. Incident response lifecycle - Ability to perform: 1. Threat hunting 2. Log correlation 3. Malware investigation 4. Phishing analysis 5. Digital forensics basics - Knowledge of security frameworks and standards: 1. ISO 27001 2. NIST Cybersecurity Framework 3. CIS Controls 4. PCI-DSS (preferred) - Relevant certifications preferred: 1. CISSP 2. CISM 3. CEH 4. GIAC (GCIH/GCIA/GCFA) 5. OSCP 6. CompTIA Security+ 7. Splunk Certified Cybersecurity Analyst 8. Microsoft Security certifications