Job Title: Information Security Analyst
Location: India
Reports To: Security & Infra Director
Role Overview
We are seeking an experienced and highly analytical Information Security Analyst. This role is responsible for monitoring, validating, investigating, and clarifying security events and incidents across the organization. The analyst will work extensively with the SOC team to improve detection coverage, tune and create correlation rules, enhance alert quality, and strengthen incident handling processes. The role will also be expected to bring hands-on experience and practical recommendations to support the implementation of SOAR capabilities, including automation use cases, playbooks, enrichment workflows, and response processes. The role requires strong hands-on investigation skills, solid understanding of digital forensics, and the ability to trace suspicious activity across endpoints, networks, cloud services, identity systems, and business applications. The analyst will work closely with SecOps engineers, security architects, network security experts, R&D, IT, and other stakeholders to ensure threats are detected, investigated, and handled effectively.
Key Responsibilities
Advanced SOC Monitoring & Event Analysis
o Monitor security events, alerts, logs, and telemetry across SIEM, XDR/EDR, identity, network, cloud, endpoint, email, and other enterprise security platforms.
o Perform advanced investigation and triage of security alerts, validate incidents, reduce false positives, and determine severity, scope, business impact, and required response actions.
o Analyze suspicious activities, attack indicators, anomalies, and behavioral patterns to identify potential threats and clarify whether events represent real security incidents.
o Conduct detailed investigations using existing security tools and data sources, including logs, endpoint telemetry, network traffic, identity events, email traces, cloud activity, and threat intelligence.
o Escalate confirmed incidents, recommend containment and remediation steps, and support incident response activities in collaboration with SecOps engineers and relevant technical teams.
o Document investigation findings, evidence, timelines, root cause, affected assets, response actions, and lessons learned in a clear and structured manner.
o Play a key role in maintaining visibility into suspicious activities and ensuring the company can detect, trace, investigate, and respond to security incidents effectively.
SIEM, Automation & Detection Engineering
o Improve the SIEM platform by tuning alerts, creating and maintaining correlation rules, enhancing use cases, improving log source coverage, and increasing detection accuracy.
o Design, recommend, and implement detection improvements based on incidents, threat intelligence, attack techniques, gaps in visibility, and operational lessons learned.
o Contribute experience and practical guidance toward the implementation of SOAR capabilities, including playbook design, automation use cases, alert enrichment, case management, and response workflows.
Incident Investigation, Forensics & Threat Hunting
o Lead deep-dive investigations of confirmed or suspected incidents, including endpoint, network, identity, cloud, and application-related security events.
o Apply digital forensics knowledge to preserve and analyze evidence, reconstruct attack timelines, understand attacker behavior, and support root-cause analysis.
o Perform threat hunting activities to proactively identify suspicious behavior, weak detection areas, persistence mechanisms, lateral movement, privilege misuse, and data exposure indicators.
o Work with SecOps engineers, security architects, network security experts, IT, R&D, cloud, and application teams to validate findings and coordinate containment, remediation, and control improvements.
o Translate investigation outcomes into improved detection logic, response procedures, playbooks, dashboards, and security monitoring coverage.
Automation, Improvement & Collaboration
o Use and improve existing security tools, while proposing practical ideas, enhancements, new detection use cases, and automation opportunities to improve SOC effectiveness.
o Collaborate with SecOps and security architecture teams on new tool implementations, onboarding of log sources, integration design, alert enrichment, response automation, and future SOAR platform planning.
o Continuously improve detection and handling processes by measuring alert quality, investigation efficiency, coverage gaps, incident trends, and lessons learned from real events.
Qualifications
o 5+ years of hands-on experience in SOC operations, incident investigation, security monitoring, threat detection, SIEM operations, security automation, digital forensics, or enterprise security operations.
o Proven experience working as an advanced SOC analyst, Tier 2/Tier 3 analyst, incident responder, detection analyst, or similar role in complex enterprise environments.
o Deep technical knowledge of SIEM, XDR/EDR, log analysis, endpoint telemetry, identity security, network security, cloud security, email security, threat intelligence, security automation, and incident response processes.
o Strong experience analyzing logs, alerts, events, and telemetry from multiple sources to validate incidents, identify attack patterns, and determine appropriate response actions.
o Hands-on experience with incident response, threat investigation, containment recommendations, root-cause analysis, attack timeline reconstruction, and post-incident improvement.
o Solid understanding of digital forensics concepts, evidence handling, endpoint investigation, malware behavior, persistence techniques, lateral movement, and attacker tactics, techniques, and procedures.
o Experience creating, tuning, and improving SIEM correlation rules, detection use cases, dashboards, alert logic, and monitoring coverage.
o Experience with security automation, playbook design, alert enrichment, case management concepts, workflow improvement, and supporting or driving SOAR implementation initiatives.
o Ability to write clear investigation summaries, incident reports, detection documentation, playbooks, runbooks, and operational recommendations.
o Hands-on experience investigating Windows, Linux, endpoint, server, cloud, identity, and network-based security events.
o Hands-on experience with SIEM, XDR, EDR, CASB, DLP, email security, vulnerability data, threat intelligence platforms, log management tools, and security automation technologies.
o Experience with monitoring, automation, orchestration, scripting, query languages, and workflow optimization.
o Experience working with R&D, infrastructure, network security, SecOps, and architecture teams in high-scale technical environments.
Work Locations: Radware Shield Square India, Chennai #131, 2nd Floor Velachery Main RoadLittle Mount - Saidapet Chennai 600015