8–12 years of experience in Cyber Security, with significant exposure to SOC operations at L3 / Senior Analyst level
Strong hands‑on experience in 24x7 SOC environments, supporting sh ift‑based operations
Advanced expertise in security incident investigation and response, including:
- High and critical severity incidents
- Cross‑domain investigations (endpoint, network, cloud, application)
Strong hands‑on experience with SIEM platforms, preferably:
- Splunk Enterprise Security, including alert analysis, correlation, and incident workflows
Hands‑on experience with EDR platforms, preferably:
- CrowdStrike Falcon, including advanced investigation and response actions
Strong knowledge of security log analysis and event correlation across:
- Endpoints
- Servers
- Network devices
- Security tools
Solid understanding of MITRE ATT&CK framework and adversary tactics, techniques, and procedures
Experience supporting Digital Forensics and Incident Response (DFIR) activities
Exposure to cloud security investigations (AWS / Azure / GCP logs and alerts)
Strong understanding of incident handling, escalation procedures, and evidence handling best practices