寻找你的下一个职业机会

按职位、技能和地点搜索招聘信息。准备申请前,先仔细了解职位要求。

找到一个吸引人的职位名称只是求职的起点。请将工作职责、招聘要求和工作条件与你的实际经历进行比较。本指南帮助你筛选机会、准备有针对性的申请材料,并确认每份申请应该在哪里提交。

此界面为简体中文。雇主发布的职位名称和描述保留原文,可能为英文。

清除筛选

搜索结果: 6,355

← 返回搜索结果

Security Operations Center Analyst - L2

SRM Technologies

地点
Chennai, Tamil Nadu, India
发布日期
2026年10月5日

申请前,请在雇主网站确认职位仍在招聘,并检查完整要求和条件。

职位描述

此界面为简体中文。雇主发布的职位名称和描述保留原文,可能为英文。

Security Operations (SOC) Analyst - L2 | SRM Tech | Onsite About SRM Tech SRM Technologies is a global digital and engineering partner delivering capabilities across data and AI, enterprise platforms, embedded and platform engineering, supply chain, and design-to-manufacturing services. We work across high-impact industries such as Mobility, Life Sciences, Healthcare, and Logistics, supporting enterprises across North America, APAC, and Europe in building intelligent, future-ready ecosystems and driving transformation at scale. As a Great Place to Work®-certified organization, we are committed to creating an environment where people can learn, grow, and thrive. We believe empowered individuals drive innovation, deliver value to customers, and play a meaningful role in shaping our collective success. At SRM Tech, every contribution matters, and we are always looking for passionate individuals who are eager to shape their careers with us. Location: Chennai Work Mode: Chennai (24/7 Rotational shift) Preferred Experience: 4 – 7 years About the Role: We are seeking a highly skilled SOC Analyst (L2) to provide hands-on security monitoring, investigation, and incident response support within a 24x7 Security Operations Center (SOC). The primary focus of this role is to ensure continuous security queue coverage, perform effective triage of medium and low-severity alerts, rapidly escalate high and critical security events, and maintain high-quality incident documentation and handoffs. The ideal candidate will have strong investigative skills across endpoint, identity, cloud, and network security domains, with practical experience using EDR platforms, case management tools, SQL-based analysis, and structured incident response procedures. Key Responsibilities: Security Monitoring & Alert Triage • Monitor and triage security alerts from multiple security platforms on a 24x7 basis. • Perform detailed analysis of medium and low-severity alerts and determine appropriate disposition. • Rapidly identify, validate, and escalate high and critical severity incidents according to defined SLAs. • Execute incident response runbooks and playbooks to ensure consistent handling of security events. • Maintain queue hygiene and ensure timely closure or escalation of alerts. Incident Investigation & Response • Conduct hands-on investigations involving endpoint, identity, cloud, email, and network-based security events. • Correlate data from multiple sources to determine attack scope, impact, and root cause. • Gather and document evidence to support incident disposition and remediation recommendations. • Participate in containment, eradication, and recovery activities during security incidents. • Support post-incident reviews and lessons learned activities. Case Management & Documentation • Manage incidents through Tines or comparable case management and workflow platforms. • Maintain accurate incident records, investigation notes, and evidence artifacts. • Produce clear and actionable updates for stakeholders and escalation teams. • Ensure high-quality shift handovers with complete context, findings, and pending actions. Security Analytics & Threat Investigation • Perform log and data analysis using Databricks, SQL, and security telemetry sources. • Investigate suspicious activity using endpoint, identity, cloud, and authentication data. • Support threat hunting activities and identify patterns indicative of malicious behavior. • Recommend improvements to alert logic, detection rules, and operational processes. Collaboration & Continuous Improvement • Collaborate with SOC Leads, Incident Responders, Cloud Operations, and Infrastructure teams. • Assist in refining operational runbooks, playbooks, and investigation procedures. • Contribute to knowledge management and continuous service improvement initiatives. Technical Skills: Endpoint Security • CrowdStrike Falcon • Microsoft Defender XDR • SentinelOne or equivalent EDR/XDR solutions Security Operations & Investigation • Security alert triage and incident investigation • Threat detection and analysis • Evidence collection and incident documentation • Runbook and playbook execution Identity & Cloud Security • Azure AD / Entra ID security monitoring • AWS and Azure security event analysis • Authentication, privilege, and identity investigations • Cloud security monitoring concepts Security Analytics • Databricks • SQL-based security analysis • Log correlation and event investigation • Data-driven threat analysis Case Management • Tines (preferred) • ServiceNow, Jira, TheHive, or equivalent incident/case management platforms SIEM Exposure (Desirable) Experience with SIEM solutions such as: • Microsoft Sentinel • Splunk • IBM QRadar • LogRhythm Note: SIEM experience is beneficial; however, practical investigation, case management, endpoint security, and multi-source analysis capabilities are considered more critical for this role. Required Qualification: • 4 to 7 years of experience in Security Operations Center (SOC) environments. • Strong hands-on experience with security investigations and incident response. • Experience analyzing endpoint, identity, and cloud security events. • Familiarity with structured case management workflows. • Proven ability to make evidence-based incident disposition decisions. • Experience supporting 24x7 security operations environments. • Strong communication, documentation, and stakeholder management skills. • Experience with triaging Identity, public cloud (AMS, Azure, GCP) email (Proofpoint or similar), and Zscaler telemetry • Experience with AI assisted enrichment and investigation tools • Experience with Atlassian Suite (JIRA, Confluence) Preferred Certifications • Microsoft SC-200 Security Operations Analyst • CompTIA CySA+ • GIAC Certified Incident Handler (GCIH) • Certified Ethical Hacker (CEH) • Microsoft AZ-500 • AWS Security Specialty •CrowdStrike Falcon Certifications (Preferred) SRM Tech is an equal opportunity employer committed to diversity, equity, inclusion, and belonging. We make all hiring decisions based on merit, without bias or discrimination, in line with applicable laws.

查找职位、比较要求,再准备申请

从你希望从事的职位或运用的技能开始搜索。调整地点和职业筛选,打开职位比较工作职责。如果没有结果,可以使用更短的关键词,或逐一移除筛选条件。

区分必备要求和优先条件,检查已列出的工作安排、薪资和地点。远程职位也可能要求特定居住国家、工作许可或工作时间重合。请向雇主确认职位信息和完整条件。

选择能够回应职位要求的真实经历,说明你的贡献,只使用能够证实的数字。遵循雇主的申请说明,并在提交前检查联系方式、文档内容和 PDF。

提交申请前的检查清单

求职常见问题

为什么有些职位使用英文?

职位名称和描述由招聘企业撰写。为避免改变招聘要求或工作条件,我们保留原文。操作界面和本指南使用简体中文。如果中文搜索没有结果,可以尝试使用职位发布语言中的名称或技能,例如“software engineer”。搜索词不会自动翻译,界面语言也不代表企业要求的申请语言。

远程职位是否允许从任何国家工作?

不一定。企业可能对居住国家、工作许可或工作时段有要求。请查看原始招聘页面中的具体条件。如果未说明,应先向企业确认,再判断能否从你所在的地区工作。“远程”标签本身并不代表没有地点限制。

搜索没有结果时应该怎么办?

尝试更通用的职位名称或单个技能,并逐一移除筛选条件。不同企业可能用不同名称描述相似工作。如果某个职位已经消失,请在企业招聘页面搜索其职位编号。扩大搜索范围不会让已经关闭的职位重新开放。

申请会通过 ResumizeAI 直接提交吗?

申请按钮会打开外部网站。请按照企业或招聘服务的说明,在该网站完成并确认提交。在 ResumizeAI 中准备简历并不等于已经申请职位。如果链接只打开企业网站,请先找到对应职位,再继续申请流程。

如何针对职位调整简历和求职信?

将招聘要求与能够解释清楚的项目、任务和成果联系起来。突出相关经历,不要添加未经实际掌握的技能或虚构成绩。在求职信中用具体例子说明申请动机,并遵守企业要求的语言和文件格式。提交前检查两份文件,确保内容准确、联系方式正确、链接可用。