Senior SOC Analyst / Detection Engineer (L2)
Company: Cywarden Global Services Location: Mohali, India (On-site) Department: Security Operations Center (SOC) Experience Level: L2 / Senior Analyst
About the Role
Cywarden Global Services is looking for a Senior SOC Analyst / Detection Engineer (L2) to join our Security Operations Center in Mohali. This role is ideal for an experienced security analyst who thrives on hands-on incident investigation, detection engineering, and proactive threat hunting across modern cloud and hybrid environments. You will act as a technical escalation point for the SOC, own incidents end-to-end, and continuously strengthen our detection capabilities.
Key Responsibilities
- Investigate and own security incidents from initial triage through containment and resolution.
- Perform advanced investigations using Microsoft Sentinel, Microsoft Defender XDR, Entra ID, Microsoft 365, Azure, OCI, Palo Alto, and other integrated security platforms.
- Develop, test, and tune Microsoft Sentinel analytics rules, KQL queries, and custom detections to improve detection accuracy and reduce false positives.
- Perform proactive threat hunting across endpoint, identity, cloud, email, and network environments.
- Correlate events from multiple log sources to identify attack patterns, lateral movement, privilege escalation, persistence, and data exfiltration.
- Analyze attacker techniques using the MITRE ATT&CK framework and improve detection coverage.
- Develop and maintain investigation playbooks, detection use cases, and SOC runbooks.
- Perform root cause analysis and provide technical recommendations to prevent recurrence of security incidents.
- Validate existing detections against emerging threats and recommend improvements.
- Support onboarding of new log sources and ensure complete security visibility across the environment.
- Collaborate with infrastructure, cloud, networking, and identity teams during investigations and remediation activities.
- Mentor L1 SOC analysts and review investigation quality.
- Prepare detailed technical incident reports and communicate findings to customers and internal stakeholders.
Required Skills & Experience
- 3–5+ years of hands-on experience in a SOC environment, with demonstrated progression to L2/senior analyst responsibilities.
- Strong working knowledge of Microsoft Sentinel (analytics rules, workbooks, incident management) and KQL query writing/tuning.
- Practical experience with Microsoft Defender XDR, Entra ID, Microsoft 365, and Azure security tooling.
- Exposure to OCI (Oracle Cloud Infrastructure) and Palo Alto firewall/security products.
- Solid understanding of the MITRE ATT&CK framework and its application to detection engineering and threat hunting.
- Experience correlating multi-source log data (endpoint, identity, cloud, email, network) to identify complex attack chains.
- Proven ability to write and maintain SOC runbooks, playbooks, and detection use-case documentation.
- Strong root cause analysis and technical report-writing skills, with the ability to communicate findings to both technical and customer-facing audiences.
- Experience mentoring or reviewing the work of junior (L1) analysts.
Nice to Have
- Relevant certifications such as SC-200, AZ-500, CompTIA CySA+, GCIH, or equivalent.
- Scripting experience (PowerShell, Python) for automation of detections or response workflows.
- Prior experience in an MSSP or managed detection & response (MDR) environment.
What We Offer
- Opportunity to work with a modern, multi-cloud security stack (Microsoft, OCI, Palo Alto) in a fast-paced SOC.
- A collaborative environment with clear growth paths from L2 toward detection engineering, threat hunting, or SOC leadership tracks.
- Exposure to end-to-end incident lifecycle management for enterprise customers.
To Apply: Interested candidates can send their updated resume with relevant experience details.
Cywarden Global Services | Mohali
Pay: ₹600,000.00 - ₹900,000.00 per year
Benefits:
- Commuter assistance
- Health insurance
- Paid time off
Work Location: In person