At Rocket India, security isn't a checkbox — it's a cornerstone of everything we build. Our Security Operations Center stands guard 24/7, ensuring that the technology powering millions of homeownership dreams stays resilient against evolving threats. As a Senior Information Security Analyst, you won't just respond to incidents — you'll shape how we detect, investigate, and neutralize them. You'll mentor the next generation of analysts, drive measurable improvements in detection quality, and serve as the calm, decisive voice when the pressure is highest. If you're ready to lead from the front lines and leave the SOC stronger than you found it, we want to talk.
About the Role
You'll operate as a senior technical leader within the SOC — owning complex investigations, driving high-severity incidents to resolution, and elevating the capability of the entire team. Here's what that looks like:
Lead end-to-end investigation of complex, multi-vector security incidents across endpoint, identity, email, network, and cloud telemetry, including P1 and P2 events
Serve as the incident commander or primary investigator on high-severity incidents, coordinating cross-functional response efforts with ThreatOps, SecOps Engineering, IT, and application teams
Reconstruct detailed attack timelines and determine blast radius by correlating diverse telemetry sources, producing executive-ready incident summaries
Mentor and coach junior and mid-level SOC analysts, conducting case reviews, providing real-time guidance during active investigations, and raising the team's technical baseline
Design, refine, and validate detection logic across SIEM, EDR, and cloud security platforms — owning the detection quality lifecycle from hypothesis through tuning and retirement
Drive measurable reduction in false positive volume and mean time to detect/respond through continuous process and tooling improvements
Identify, scope, and champion automation opportunities, partnering with SecOps Engineering to build SOAR playbooks that eliminate repetitive manual work
Author and maintain advanced triage and investigation runbooks, ensuring consistency and scalability across shifts
Lead post-incident reviews and after-action reports, translating lessons learned into concrete detection, process, or architecture improvements
Proactively hunt for threats using hypothesis-driven methodologies, threat intelligence, and behavioral analytics
Represent SOC capabilities and findings to senior leadership and cross-functional stakeholders with clear, concise communication
Participate in and help design tabletop exercises, purple team engagements, and response drills to stress-test and strengthen readiness
Stay current on emerging threats, attacker tradecraft, and industry trends, feeding relevant intelligence back into detection and response strategies
About You
Minimum Qualifications
3+ years in an information security analyst or SOC analyst role with demonstrated progression in responsibility
5+ years of experience in a technology role
Bachelor's degree in information assurance, computer science, or a related field, or equivalent experience
Deep hands-on experience with SIEM platforms, including advanced query building, correlation rule development, and large-scale log analysis
Strong proficiency with endpoint detection and response tooling, including the ability to conduct deep-dive forensic investigations
Expert-level understanding of operating systems (Windows, macOS, Linux/Unix) internals, network protocols, and traffic analysis
Ability to write scripts and automation (Python, PowerShell, or equivalent) to support investigations and operational efficiency
Strong command of the MITRE ATT&CK framework with the ability to map observed activity, identify coverage gaps, and inform detection strategy
Proven experience owning incidents through the full incident response lifecycle — detection, containment, eradication, recovery, and post-incident review
Demonstrated ability to lead under pressure, make sound decisions with incomplete information, and communicate clearly to both technical and non-technical audiences
Experience mentoring or providing technical guidance to other analysts
Clear, structured written communication — capable of producing investigation documentation, executive summaries, and after-action reports
Schedule flexibility — available to work outside standard business hours, including evenings, weekends, and holidays, as incident severity and volume demand.
Experience serving as incident commander or lead investigator on P1 incidents in an enterprise environment
Demonstrated track record of designing or significantly improving detection logic with measurable impact on alert fidelity
Hands-on experience building or operationalizing SOAR playbooks and security automation workflows
Industry certifications such as GCIH, GCFA, GCIA, CISSP, or CISM
Experience with cloud security monitoring and incident response across AWS, Azure, or GCP environments
Familiarity with threat hunting methodologies and proactive detection approaches
Experience in the mortgage, financial services, or another regulated industry
Prior experience contributing to or leading purple team exercises.
What You Will Get
At Rocket India, senior talent gets senior investment. You'll enjoy comprehensive health and wellness benefits, a competitive compensation package that reflects your expertise, and continuous professional development — including support for advanced certifications and conference attendance. You'll work with best-in-class security tooling, collaborate with brilliant people across the globe, and have genuine influence over how we protect one of America's most recognized brands. We foster a culture where leadership is earned through impact, not title, and where your ideas for making the SOC better don't just get heard — they get built.
About Us
Rocket India, registered as NSM Services Private Limited and formerly Mr. Cooper, is a wholly owned subsidiary of Rocket Mortgage, LLC, headquartered in Detroit, Michigan. As a core part of Rocket's global ecosystem, Rocket India helps shape the future of home financing through technology, innovation, operations, product, and customer-focused solutions. Our teams build scalable platforms and digital experiences that simplify mortgage origination and servicing while supporting Rocket's mission to "Help Everyone Home."
We are committed to providing a fair and inclusive workplace for all team members and applicants. All qualified applicants will receive consideration for employment without regard to sex, religion, caste, disability, or gender identity, consistent with applicable Indian law, including the Constitution of India, the Code on Wages, 2019, the Rights of Persons with Disabilities Act, 2016, and the Transgender Persons (Protection of Rights) Act, 2019. We welcome applications from persons with disabilities and from all sections of society.