Experience
2 - 4 yrs
Job Location
Hyderabad, India
Vacancy
1
Designation
Security Analyst
Job Type
Not specified
Job Description
< h3> Role Overview< /h3> < p> The SOC L1 Analyst is responsible for 24x7 security monitoring, alert triage, and initial investigation across enterprise security tools including SIEM, EDR/XDR, Cloud, DLP, DAM, and Email Security. The role focuses on early threat detection, accurate classification, and timely escalation of security incidents in line with defined SLAs and SOC procedures.< /p> < h3> Key Responsibilities< /h3> < ul> < li> Monitor and triage alerts from SIEM, EDR/XDR, Cloud (Azure/AWS), DLP, DAM, and Email Security platforms< /li> < li> Perform initial validation and classification of alerts (True Positive / False Positive / Benign)< /li> < li> Investigate common threats such as phishing, malware, brute force attacks, and anomalous logins etc.< /li> < li> Conduct IOC enrichment and basic threat analysis (IP, domain, hash reputation checks)< /li> < li> Perform basic endpoint investigation (process tree, file activity, command-line review)< /li> < li> Analyze email security alerts, including phishing and header analysis< /li> < li> Validate DLP alerts for potential data leakage and DAM alerts for unauthorized database access< /li> < li> Create, update, and manage incident tickets in JIRA with proper documentation< /li> < li> Follow SOC playbooks and escalate confirmed incidents to L2 within SLA timelines< /li> < li> Collaborate with IT and security teams for incident validation and response support< /li> < /ul> < h3> Required Qualifications< /h3> < ul> < li> 2 to 4 years of experience in a Security Operations Center (SOC) or similar role< /li> < li> Bachelor degree in Cybersecurity, Computer Science, IT, or related field< /li> < li> Hands-on experience with at least one SIEM platform (e.g., Sentinel, Splunk, QRadar) and EDR/XDR tools (e.g., Microsoft Defender, CrowdStrike, SentinelOne)< /li> < li> Basic understanding of cloud security logs (Azure AD, AWS CloudTrail)< /li> < li> Familiarity with DLP and DAM concepts< /li> < li> Knowledge of email security and phishing analysis techniques< /li> < li> Relevant certifications preferred: CompTIA Security+, CEH, CySA+, SC-200< /li> < /ul> < h3> Core Competencies< /h3> < ul> < li> Strong understanding of networking fundamentals (TCP/IP, DNS, HTTP/S, ports protocols)< /li> < li> Knowledge of common cyber threats: phishing, malware, ransomware, brute force etc.< /li> < li> Basic awareness of MITRE ATTCK framework< /li> < li> Ability to analyze logs and correlate events across multiple tools< /li> < li> Good understanding of incident triage and escalation workflows< /li> < li> Strong analytical thinking and attention to detail< /li> < li> Effective communication and documentation skills< /li> < li> Ability to work in a 24x7 rotational shift environment< /li> < /ul>
Disclaimer : This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
