Soc Analyst 1 - SIEM / Google Secops

KPMG Assurance and Consulting Services LLP
Posted on
KPMG Assurance and Consulting Services LLP logo

Experience
1 - 4 yrs
Salary (CTC)
₹7L - ₹10L
Job Location
Bengaluru, India
Vacancy
13
Designation
SOC Analyst
Job Type
Not specified

Job Description

Job Summary

We are seeking a skilled and proactive SOC Analyst / Security Operations Engineer with 4+ years of cybersecurity experience and hands-on expertise in Google SecOps (Chronicle). The ideal candidate will be responsible for monitoring, investigating, and responding to security incidents, developing threat detection use cases, performing threat hunting activities, and enhancing the organization's security posture through effective use of SIEM and security technologies.

Key Responsibilities

  • Monitor, analyze, and investigate security alerts using Google SecOps (Chronicle SIEM).
  • Perform incident triage, analysis, containment, eradication, and recovery activities.
  • Develop, tune, and optimize detection rules, correlation searches, and use cases.
  • Conduct threat hunting activities to identify advanced threats and suspicious activities.
  • Analyze logs from multiple security devices including firewalls, EDR, IDS/IPS, proxy, email security, and cloud platforms.
  • Investigate phishing, malware, ransomware, insider threats, and privilege misuse incidents.
  • Create and maintain incident response playbooks and standard operating procedures.
  • Support client audits, compliance requirements, and security assessments.
  • Collaborate with IT, network, cloud, and application teams during security investigations.
  • Prepare incident reports, Root Cause Analysis (RCA), and management dashboards.
  • Stay updated on emerging cyber threats, vulnerabilities, and attack techniques.

Required Skills & Experience

Google SecOps (Mandatory)

  • Hands-on experience with Google SecOps / Chronicle SIEM.
  • Expertise in log ingestion, parsing, normalization, and troubleshooting.
  • Experience in rule creation, detection engineering, and alert tuning.
  • Knowledge of UDM (Unified Data Model) and YARA-L queries.
  • Experience with dashboards, investigations, and case management.

SOC & Security Operations

  • 4+ years of experience in Security Operations Center (SOC) environments.
  • Strong understanding of Incident Response lifecycle.
  • Experience monitoring and investigating security events and alerts.
  • Knowledge of SIEM concepts and security monitoring methodologies.
  • Experience with Threat Intelligence and Threat Hunting activities.

Security Technologies

  • Endpoint Detection & Response (EDR) solutions such as CrowdStrike, Microsoft Defender, SentinelOne, or Carbon Black.
  • IDS/IPS technologies.
  • Email security solutions.
  • Web Proxy and Firewall technologies.
  • Vulnerability Management tools (Qualys, Nessus, Rapid7, etc.).

Cloud Security

  • Good understanding of AWS, Azure, or Google Cloud security concepts.
  • Experience monitoring cloud-native security logs and events.
  • Knowledge of IAM, cloud networking, and security controls.

Technical Knowledge

  • Network Security fundamentals (TCP/IP, DNS, HTTP/S, VPN, Routing).
  • MITRE ATT&CK Framework.
  • Cyber Kill Chain methodology.
  • Malware analysis fundamentals.
  • Log analysis and event correlation techniques.
  • Operating Systems: Windows, Linux, and Unix.
  • Scripting knowledge in Python, PowerShell, or Bash is preferred.

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.