Job Description
We are hiring for Senior Security Analyst -SOC at Gurgaon
Job Title: Senior Security Analyst Security Operations Center (SOC)
Location: Gurgaon, India (Work from Office)
Work Mode: Full-time | On-site
Flexibility to support 24x7 operational requirements, as needed
Role Overview
The Senior Security Analyst serves as the technical lead within the Security Operations Center (SOC), leading complex cyber security investigations, enhancing detection capabilities, improving incident response, coordinating with the MSSP and internal teams, and supporting the SOC Manager through executive reporting, service governance, and continuous improvement initiatives.
Core Responsibilities
- Lead investigation of complex security incidents escalated by MSSP and SOC analysts.
- Validate incident severity, business impact, attack scope, and response actions.
- Coordinate containment, eradication, recovery, and post-incident activities.
- Design, develop, and optimize SIEM detection use cases and detection logic.
- Perform proactive threat hunting using intelligence-driven methodologies.
- Review MSSP investigation quality, SLA adherence, and recommend improvements.
- Support onboarding of new log sources and improve SOAR playbooks.
- Prepare daily, weekly, monthly, and quarterly SOC reports, dashboards, KPIs, and CISO presentation inputs.
- Coordinate with IT Infrastructure, Cloud, Network, Identity, and Application teams until security actions are closed.
- Maintain SOC documentation, playbooks, runbooks, and technical standards.
- Drive SOC maturity, automation, and continuous improvement initiatives.
Required Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related discipline.
Required Experience
- 8-10 years of Security Operations experience, with minimum 4 years as an L2 SOC Analyst or equivalent.
- Experience with MSSP environments, SIEM, EDR, Incident Response, Threat Hunting, and Detection Engineering.
Technical Skills
- SIEM: CrowdStrike NGSIEM, Microsoft Sentinel, Splunk, QRadar
- EDR: CrowdStrike Falcon, Microsoft Defender
- Cloud: Azure, Microsoft Entra ID, AWS (preferred).
- Email Security, SOAR
- Frameworks: MITRE ATT&CK, NIST CSF, ISO 27001.
Preferred Certifications
- CrowdStrike Falcon Certification.
Key Competencies
- Ownership and accountability
- Technical leadership
- Stakeholder management
- Executive reporting and presentation
- Analytical problem solving
- Communication and collaboration
Key Performance Indicators
- High-priority incident investigation within SLA.
- Improved detection coverage and reduced false positives.
- Timely executive dashboards and reporting.
- Threat hunting outcomes and SOC maturity improvements.
- MSSP service quality and action-item closure.
Work environment & availability
- Willingness to support 24x7 operations as required, including after-hours and weekend support during critical or high-severity incidents.
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
