Найдите следующую карьерную возможность

Ищите вакансии по профессии, навыку и местоположению. Изучите требования, прежде чем готовить отклик.

Хороший поиск работы не заканчивается на привлекательном названии должности. Сопоставьте обязанности, требования и условия со своим опытом. Это руководство поможет выбрать подходящие возможности, подготовить документы и проверить, куда отправлять каждый отклик.

Интерфейс на русском языке. Названия и описания вакансий сохраняются на языке публикации работодателя, в том числе на английском.

Сбросить фильтры

Результаты: 6 355

← Вернуться к результатам

Security Operations Center Analyst - L2

SRM Technologies

Местоположение
Chennai, Tamil Nadu, India
Опубликовано
5 окт. 2026 г.

Перед откликом проверьте на сайте работодателя, открыта ли вакансия, и ознакомьтесь с полными условиями.

Описание вакансии

Интерфейс на русском языке. Названия и описания вакансий сохраняются на языке публикации работодателя, в том числе на английском.

Security Operations (SOC) Analyst - L2 | SRM Tech | Onsite About SRM Tech SRM Technologies is a global digital and engineering partner delivering capabilities across data and AI, enterprise platforms, embedded and platform engineering, supply chain, and design-to-manufacturing services. We work across high-impact industries such as Mobility, Life Sciences, Healthcare, and Logistics, supporting enterprises across North America, APAC, and Europe in building intelligent, future-ready ecosystems and driving transformation at scale. As a Great Place to Work®-certified organization, we are committed to creating an environment where people can learn, grow, and thrive. We believe empowered individuals drive innovation, deliver value to customers, and play a meaningful role in shaping our collective success. At SRM Tech, every contribution matters, and we are always looking for passionate individuals who are eager to shape their careers with us. Location: Chennai Work Mode: Chennai (24/7 Rotational shift) Preferred Experience: 4 – 7 years About the Role: We are seeking a highly skilled SOC Analyst (L2) to provide hands-on security monitoring, investigation, and incident response support within a 24x7 Security Operations Center (SOC). The primary focus of this role is to ensure continuous security queue coverage, perform effective triage of medium and low-severity alerts, rapidly escalate high and critical security events, and maintain high-quality incident documentation and handoffs. The ideal candidate will have strong investigative skills across endpoint, identity, cloud, and network security domains, with practical experience using EDR platforms, case management tools, SQL-based analysis, and structured incident response procedures. Key Responsibilities: Security Monitoring & Alert Triage • Monitor and triage security alerts from multiple security platforms on a 24x7 basis. • Perform detailed analysis of medium and low-severity alerts and determine appropriate disposition. • Rapidly identify, validate, and escalate high and critical severity incidents according to defined SLAs. • Execute incident response runbooks and playbooks to ensure consistent handling of security events. • Maintain queue hygiene and ensure timely closure or escalation of alerts. Incident Investigation & Response • Conduct hands-on investigations involving endpoint, identity, cloud, email, and network-based security events. • Correlate data from multiple sources to determine attack scope, impact, and root cause. • Gather and document evidence to support incident disposition and remediation recommendations. • Participate in containment, eradication, and recovery activities during security incidents. • Support post-incident reviews and lessons learned activities. Case Management & Documentation • Manage incidents through Tines or comparable case management and workflow platforms. • Maintain accurate incident records, investigation notes, and evidence artifacts. • Produce clear and actionable updates for stakeholders and escalation teams. • Ensure high-quality shift handovers with complete context, findings, and pending actions. Security Analytics & Threat Investigation • Perform log and data analysis using Databricks, SQL, and security telemetry sources. • Investigate suspicious activity using endpoint, identity, cloud, and authentication data. • Support threat hunting activities and identify patterns indicative of malicious behavior. • Recommend improvements to alert logic, detection rules, and operational processes. Collaboration & Continuous Improvement • Collaborate with SOC Leads, Incident Responders, Cloud Operations, and Infrastructure teams. • Assist in refining operational runbooks, playbooks, and investigation procedures. • Contribute to knowledge management and continuous service improvement initiatives. Technical Skills: Endpoint Security • CrowdStrike Falcon • Microsoft Defender XDR • SentinelOne or equivalent EDR/XDR solutions Security Operations & Investigation • Security alert triage and incident investigation • Threat detection and analysis • Evidence collection and incident documentation • Runbook and playbook execution Identity & Cloud Security • Azure AD / Entra ID security monitoring • AWS and Azure security event analysis • Authentication, privilege, and identity investigations • Cloud security monitoring concepts Security Analytics • Databricks • SQL-based security analysis • Log correlation and event investigation • Data-driven threat analysis Case Management • Tines (preferred) • ServiceNow, Jira, TheHive, or equivalent incident/case management platforms SIEM Exposure (Desirable) Experience with SIEM solutions such as: • Microsoft Sentinel • Splunk • IBM QRadar • LogRhythm Note: SIEM experience is beneficial; however, practical investigation, case management, endpoint security, and multi-source analysis capabilities are considered more critical for this role. Required Qualification: • 4 to 7 years of experience in Security Operations Center (SOC) environments. • Strong hands-on experience with security investigations and incident response. • Experience analyzing endpoint, identity, and cloud security events. • Familiarity with structured case management workflows. • Proven ability to make evidence-based incident disposition decisions. • Experience supporting 24x7 security operations environments. • Strong communication, documentation, and stakeholder management skills. • Experience with triaging Identity, public cloud (AMS, Azure, GCP) email (Proofpoint or similar), and Zscaler telemetry • Experience with AI assisted enrichment and investigation tools • Experience with Atlassian Suite (JIRA, Confluence) Preferred Certifications • Microsoft SC-200 Security Operations Analyst • CompTIA CySA+ • GIAC Certified Incident Handler (GCIH) • Certified Ethical Hacker (CEH) • Microsoft AZ-500 • AWS Security Specialty •CrowdStrike Falcon Certifications (Preferred) SRM Tech is an equal opportunity employer committed to diversity, equity, inclusion, and belonging. We make all hiring decisions based on merit, without bias or discrimination, in line with applicable laws.

Ищите, сравнивайте и готовьте отклик

Начните с профессии или навыка, который хотите использовать. Настройте фильтры местоположения и профессии, затем откройте вакансии и сравните обязанности. Если результатов нет, попробуйте более короткий запрос или убирайте по одному фильтру.

Отделите обязательные требования от пожеланий. Проверьте график, вознаграждение и местоположение, если они указаны. Удалённая работа тоже может требовать проживания в определённой стране, разрешения на работу или совпадения рабочих часов. Уточните актуальность вакансии и полные условия у работодателя.

Выберите реальные примеры из своего опыта, соответствующие требованиям вакансии. Объясните свой вклад и используйте только подтверждаемые цифры. Следуйте инструкциям работодателя и перед отправкой проверьте контакты, содержание и отображение PDF.

Перед отправкой отклика

Вопросы о поиске работы

Почему некоторые вакансии написаны на английском?

Работодатели сами составляют названия и описания. Мы сохраняем исходный текст, чтобы не изменить требования или условия. Навигация и это руководство доступны на русском. Если запрос на русском не даёт результатов, попробуйте название должности или навыка на языке объявления, например «software engineer».

Можно ли работать удалённо из любой страны?

Не всегда. Компания может ограничивать страны проживания, требовать разрешение на работу или доступность в определённые часы. Изучите исходное объявление. Если этих сведений нет, уточните условия у работодателя, прежде чем считать, что работа доступна из вашего местоположения.

Что делать, если поиск не даёт результатов?

Попробуйте более общее название должности или один навык и убирайте фильтры по одному. Компании по-разному называют похожие роли. Если конкретная вакансия исчезла, найдите её номер на карьерной странице компании. Расширение поиска не открывает закрытую вакансию заново.

Отправляется ли отклик через ResumizeAI?

Кнопка отклика открывает внешний сайт. Следуйте инструкциям работодателя или платформы подбора и подтвердите отправку там. Подготовка резюме в ResumizeAI сама по себе не отправляет отклик. Если ссылка ведёт только на сайт компании, сначала найдите нужную вакансию.

Как адаптировать резюме и сопроводительное письмо?

Свяжите требования с проектами, задачами и результатами, которые можете объяснить. Выделите подходящий опыт, не придумывая навыки и достижения. В письме объясните свой интерес и приведите конкретный пример. Соблюдайте запрошенные язык и формат и проверьте оба документа перед отправкой.