Job Responsibilities:
- Monitor and investigate security alerts generated from Microsoft Defender, Microsoft XDR, and Microsoft Sentinel.
- Perform triage, analysis, containment, and remediation of security incidents in accordance with established incident response procedures.
- Serve as the primary escalation point for security alerts, incidents, and threat investigations.
- Configure, tune, and maintain security alerts, detection rules, analytics rules, and automated response actions within Microsoft security platforms.
- Analyze security events and logs to identify potential threats, suspicious activities, and indicators of compromise.
- Lead security incident investigations and coordinate response efforts with internal teams and client stakeholders.
- Support incident response activities including evidence collection, root cause analysis, documentation, and post-incident reviews.
- Review and recommend improvements to security monitoring, alerting, detection capabilities, and incident handling processes.
- Assist in the development and maintenance of security use cases, playbooks, and standard operating procedures.
- Conduct routine security health checks and validate the effectiveness of deployed security controls.
- Identify security gaps and recommend practical security improvement initiatives to strengthen organizational and client security posture.
- Collaborate with technical teams to investigate vulnerabilities, remediation activities, and security-related issues.
- Support security operations across multiple client environments within an MSP environment when applicable.
- Prepare security reports detailing incidents, trends, risks, and recommendations.
- Stay current with emerging cybersecurity threats, attack techniques, and Microsoft security best practices.
- Handle additional tasks assigned by the Manager, Sr. Managing Partner, and President.
Job Requirements:
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field.
- Minimum of 2-4 years of experience in Security Operations, SOC, Incident Response, or Cybersecurity-related roles.
- Hands-on experience with Microsoft Defender, Microsoft XDR, and Microsoft Sentinel.
- Experience configuring, tuning, and managing security alerts, detection rules, and monitoring dashboards.
- Experience investigating and responding to cybersecurity incidents, including phishing, malware, ransomware, suspicious logins, and unauthorized access attempts.
- Understanding of incident response processes, threat detection methodologies, and security monitoring best practices.
- Knowledge of Microsoft 365, Microsoft Azure, Windows Server, Active Directory, and Entra ID.
- Experience reviewing endpoint, identity, email, and cloud security logs.
- Experience working within a Managed Service Provider (MSP) environment is preferred.
- Strong analytical, troubleshooting, and problem-solving skills.
- Strong verbal and written English communication skills.
- Ability to communicate technical findings and recommendations to both technical and non-technical stakeholders.
- Familiarity with cybersecurity frameworks, standards, and security best practices is an advantage.
- Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900) is preferred.
- Microsoft Certified: Security Operations Analyst Associate (SC-200), CompTIA Security+, or equivalent cybersecurity certifications are advantageous but not required.
- Demonstrated hands-on experience with Microsoft security technologies may be considered in lieu of certification credentials.
- Can work on different shifts and occasional scheduled weekend shifts.
- Amenable to provide on-call support and render overtime during security incidents, critical events, or emergency situations.
Pay: ₹500,000.00 - ₹1,000,000.00 per year
Benefits:
- Health insurance
- Leave encashment
- Paid sick time
- Paid time off
- Provident Fund
Application Question(s):
- What is your current CTC?
- What is your expected CTC?
Experience:
- Security analysis: 3 years (Preferred)
Shift availability:
Work Location: Hybrid remote in Bengaluru, Karnataka (Bengaluru, 560000, Bengaluru Urban District)