寻找你的下一个职业机会

按职位、技能和地点搜索招聘信息。准备申请前,先仔细了解职位要求。

找到一个吸引人的职位名称只是求职的起点。请将工作职责、招聘要求和工作条件与你的实际经历进行比较。本指南帮助你筛选机会、准备有针对性的申请材料,并确认每份申请应该在哪里提交。

此界面为简体中文。雇主发布的职位名称和描述保留原文,可能为英文。

清除筛选

搜索结果: 6,355

← 返回搜索结果

SOC Analyst (L1 / L2 / L3)

ADMIN

地点
Hyderabad, Telangana, India
发布日期
2026年10月5日

申请前,请在雇主网站确认职位仍在招聘,并检查完整要求和条件。

职位描述

此界面为简体中文。雇主发布的职位名称和描述保留原文,可能为英文。

At Provido Global, we’re more than a technology company. We are a global hub of innovation, creativity, and engineering excellence. Our teams design and deliver intelligent, secure, and high-performance digital solutions that help organizations modernize operations, scale their platforms, and succeed in an increasingly digital world. As part of a dynamic international ecosystem, we bring together forward-thinking engineers, technology specialists, designers, and delivery professionals who transform ideas into scalable, real-world solutions with measurable business impact. If you are motivated by challenge, inspired by technology, and ready to grow with a company that truly invests in its people, your journey starts here. Why We Need You The SOC Analyst is responsible for security monitoring, alert triage, incident investigation, threat analysis, and escalation support within the Security Operations Center. This role supports the protection of enterprise systems by identifying suspicious activity, analysing security events, documenting investigations, and coordinating response activities according to established procedures. We are hiring SOC Analysts across multiple levels (L1, L2, and L3). The role level will be determined based on the candidate’s experience, technical capability, and hands-on exposure in cybersecurity operations. The role is based on-site in Hyderabad and is designed for candidates who can operate effectively in a structured, shift-based environment while coordinating with global teams to operate Security Operations in a Follow-the-Sun model. What You’ll Be Doing SOC Analyst (L1) Monitor security alerts and events across SIEM, endpoint, network, email, and cloud security tools. Perform first-level triage to validate alerts, identify false positives, and determine whether escalation is required. Escalate suspected or confirmed incidents to senior SOC analysts, incident responders, or relevant technical teams according to defined runbooks. Document alerts, investigations, and response actions accurately in ticketing and case management systems for audit and reporting purposes. Correlate logs and events from multiple sources to identify suspicious patterns, indicators of compromise, or repeated attack activity. Support 24/7 monitoring operations through shift work, handovers, and adherence to service level expectations where applicable. Communicate effectively in English when documenting incidents, coordinating with internal stakeholders, or supporting regional operations. Maintain awareness of current threats affecting enterprise environments. SOC Analyst (L2) Monitor security alerts and events across SIEM, endpoint, network, email, and cloud security tools. Perform L2 triage and investigation of security alerts, including validation, enrichment, impact assessment, containment recommendations, and escalation where required. Escalate suspected or confirmed incidents to incident responders, platform owners, infrastructure teams, or business stakeholders according to defined runbooks and severity criteria. Document investigations, response actions, evidence, and closure rationale accurately in ticketing and case management systems for audit, reporting, and knowledge management purposes. Correlate logs and events from multiple sources to identify suspicious patterns, indicators of compromise, or repeated attack activity. Administer and support security platforms by performing user access updates, configuration changes, log source onboarding, connector health checks, alert tuning, rule updates, dashboard maintenance, and operational troubleshooting. Support 24/7 monitoring operations through shift work, handovers, and adherence to service level expectations where applicable. Communicate effectively in English when documenting incidents, coordinating with internal stakeholders, and supporting regional or global security operations. Maintain awareness of current threats affecting enterprise environments across financial services, retail, logistics, telecommunications, and other industries. SOC Analyst (L3) Lead advanced triage, investigation, and analysis of high-severity alerts and incidents across SIEM, endpoint, network, email, identity, and cloud security platforms. Perform deep-dive log analysis, event correlation, threat hunting, and root-cause analysis to identify attack patterns, indicators of compromise, and control gaps. Administer and maintain security platforms, including configuration updates, rule tuning, alert logic validation, data source onboarding, connector health checks, and access administration where applicable. Develop, refine, and maintain detection use cases, correlation rules, dashboards, playbooks, standard operating procedures, and response runbooks. Coordinate incident response activities with security engineering, infrastructure, cloud, network, identity, application, and business teams to ensure timely containment and remediation. Provide technical guidance, quality review, and mentoring to L1 and L2 SOC analysts, including escalation review and investigation coaching. Ensure accurate documentation of investigations, evidence, actions taken, lessons learned, and control recommendations in ticketing and case management systems for reporting and audit purposes. Support 24/7 SOC operations through structured handovers, shift support, service level adherence, and collaboration with global teams operating in a Follow-The-Sun model. What You Bring to the Team SOC Analyst (L1) Bachelor’s degree or currently completed studies in Cybersecurity, Information Technology, Computer Science, Systems Engineering, or a related discipline. 2+ years of experience in cybersecurity, IT support, network operations, security monitoring, or a related technical role. Basic understanding of networking, operating systems, identity and access concepts, and common cyber threats such as phishing, malware, and unauthorized access attempts. Familiarity with SIEM platforms, endpoint detection tools, or log analysis concepts acquired through work experience, academic training, internships, or labs. Ability to write clear incident notes, follow procedures consistently, and work effectively in a structured operational environment. Working proficiency in English is strongly preferred to support multinational teams and stakeholders. Availability to work on-site in Hyderabad, India required. SOC Analyst (L2) Bachelor’s degree or currently completed studies in Cybersecurity, Information Technology, Computer Science, Systems Engineering, or a related discipline. 3–5 years of experience in cybersecurity operations, SOC monitoring, incident investigation, security engineering support, platform administration, or a related technical role. Strong understanding of networking, operating systems, identity and access concepts, cloud services, attacker techniques, and common cyber threats such as phishing, malware, credential compromise, and unauthorized access attempts. Hands-on experience with SIEM, EDR, email security, vulnerability management, cloud security, identity security, or case management platforms, including basic administration or operational support activities. Ability to write clear investigation notes, follow runbooks, support detection tuning, maintain operational documentation, and work effectively in a structured security operations environment. Working proficiency in English is strongly preferred to support multinational teams and stakeholders. Availability to work on-site in Hyderabad, India required. SOC Analyst (L3) Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Systems Engineering, or a related discipline, or equivalent practical experience. 5+ years of experience in cybersecurity operations, including hands-on SOC analyst experience with exposure to incident response, threat hunting, or detection engineering. Practical experience administering or supporting security platforms such as SIEM, EDR/XDR, SOAR, email security gateways, cloud security tools, vulnerability management platforms, identity security tools, or network security monitoring solutions. Strong understanding of security monitoring, cyber kill chain or MITRE ATT&CK techniques, incident response lifecycle, log analysis, endpoint telemetry, network protocols, authentication flows, and common attack methods. Ability to tune alerts, validate detection logic, assess control effectiveness, and recommend improvements to monitoring coverage and response procedures. Strong written and verbal communication skills, with the ability to document investigations clearly and brief technical and non-technical stakeholders. Working proficiency in English is required to support multinational teams and stakeholders. Availability to work on-site in Hyderabad, India required. Preferred Skills Professional certifications such as CompTIA Security+, CySA+, GCIA, GCIH, GCFA, CEH, SC-200, AZ-500, Microsoft Security Operations Analyst, or equivalent security operations credentials. Hands-on experience with Microsoft Sentinel, Microsoft Defender XDR, Splunk, QRadar, CrowdStrike, Palo Alto, Fortinet, Proofpoint, Zscaler, or comparable enterprise security technologies. Experience onboarding log sources, maintaining connectors, building dashboards, managing alert queues, integrating SOAR workflows, or supporting security platform upgrades. Exposure to cloud security monitoring across Microsoft Azure, AWS, Google Cloud, or hybrid enterprise environments. Experience working in regulated or compliance-focused environments with strong documentation, control adherence, evidence management, and audit support expectations. Ability to mentor junior analysts, lead technical escalations, and contribute to continuous improvement of SOC processes, detection maturity, and operational reporting. Experience supporting SOC, NOC, help desk, IT operations, or managed security environments. Experience with use case development, alert rule tuning, automation playbooks, threat intelligence enrichment, log source integration, or platform health monitoring. Understanding of compliance-focused environments and the importance of documentation, control adherence, and audit support. Strong customer service mindset and the ability to coordinate professionally with internal users, technical teams, and business stakeholders. Why You’ll Love Working with Us Employee Benefits & Advantages At Provido Global, we value our employees and nurture a culture of progress and creativity. Our team members enjoy a supportive, inclusive, and growth-focused environment. Competitive Compensation & Performance Incentives Provido Global offers an attractive salary package and performance-based bonuses to recognize and reward your contribution.Flexible Working Options We support remote and hybrid working models to help you maintain a healthy work-life balance.Health & Well-being Support We provide comprehensive health insurance, wellness initiatives, and resources to support both physical and mental well-being.Career Advancement & Development Programs We invest in continuous learning through training programs, mentorship, and clearly defined career development paths.Team-Oriented & Inclusive Workplace Our culture is built on diversity, inclusion, and collaboration. Every voice matters and innovation is encouraged.Team Events & Social Activities We organize regular team-building activities and social events to strengthen relationships and create a positive, connected workplace.

查找职位、比较要求,再准备申请

从你希望从事的职位或运用的技能开始搜索。调整地点和职业筛选,打开职位比较工作职责。如果没有结果,可以使用更短的关键词,或逐一移除筛选条件。

区分必备要求和优先条件,检查已列出的工作安排、薪资和地点。远程职位也可能要求特定居住国家、工作许可或工作时间重合。请向雇主确认职位信息和完整条件。

选择能够回应职位要求的真实经历,说明你的贡献,只使用能够证实的数字。遵循雇主的申请说明,并在提交前检查联系方式、文档内容和 PDF。

提交申请前的检查清单

求职常见问题

为什么有些职位使用英文?

职位名称和描述由招聘企业撰写。为避免改变招聘要求或工作条件,我们保留原文。操作界面和本指南使用简体中文。如果中文搜索没有结果,可以尝试使用职位发布语言中的名称或技能,例如“software engineer”。搜索词不会自动翻译,界面语言也不代表企业要求的申请语言。

远程职位是否允许从任何国家工作?

不一定。企业可能对居住国家、工作许可或工作时段有要求。请查看原始招聘页面中的具体条件。如果未说明,应先向企业确认,再判断能否从你所在的地区工作。“远程”标签本身并不代表没有地点限制。

搜索没有结果时应该怎么办?

尝试更通用的职位名称或单个技能,并逐一移除筛选条件。不同企业可能用不同名称描述相似工作。如果某个职位已经消失,请在企业招聘页面搜索其职位编号。扩大搜索范围不会让已经关闭的职位重新开放。

申请会通过 ResumizeAI 直接提交吗?

申请按钮会打开外部网站。请按照企业或招聘服务的说明,在该网站完成并确认提交。在 ResumizeAI 中准备简历并不等于已经申请职位。如果链接只打开企业网站,请先找到对应职位,再继续申请流程。

如何针对职位调整简历和求职信?

将招聘要求与能够解释清楚的项目、任务和成果联系起来。突出相关经历,不要添加未经实际掌握的技能或虚构成绩。在求职信中用具体例子说明申请动机,并遵守企业要求的语言和文件格式。提交前检查两份文件,确保内容准确、联系方式正确、链接可用。