Job Title: SOC Analyst L3
Company: F9 Infotech
Location: Kochi, Kerala
Experience: 4-8 Years
Employment Type: Full-Time
Role Summary
F9 Infotech is looking for an experienced SOC Analyst L3 to lead advanced threat detection, incident response, threat hunting, and security operations. The ideal candidate will have strong expertise in SIEM platforms, EDR/XDR solutions, cloud security, malware analysis, and incident investigation while mentoring L1/L2 analysts and enhancing the organization's overall security posture.
Key Responsibilities
- Lead the investigation, analysis, containment, eradication, and recovery of complex security incidents.
- Perform proactive threat hunting using SIEM, EDR/XDR, and threat intelligence platforms.
- Monitor, analyze, and respond to advanced cyber threats across endpoints, servers, networks, cloud, and applications.
- Conduct malware analysis, IOC validation, and forensic investigations.
- Fine-tune SIEM use cases, correlation rules, dashboards, and detection logic to improve security monitoring.
- Analyze logs from firewalls, IDS/IPS, WAF, VPN, Active Directory, email security, cloud platforms, and endpoint security solutions.
- Develop and maintain incident response playbooks, SOPs, and security documentation.
- Collaborate with infrastructure, cloud, and application teams to remediate security vulnerabilities and incidents.
- Mentor and provide technical guidance to SOC L1 and L2 analysts.
- Support vulnerability management, security assessments, and compliance initiatives.
- Prepare detailed technical and executive incident reports with remediation recommendations.
- Stay updated with emerging threats, attack techniques, and industry best practices.
Required Technical Skills
- Hands-on experience with SIEM platforms such as Microsoft Sentinel, Splunk, IBM QRadar, ArcSight, or LogRhythm.
- Experience with EDR/XDR solutions such as Microsoft Defender, CrowdStrike Falcon, SentinelOne, or Cortex XDR.
- Strong knowledge of Windows, Linux, Active Directory, TCP/IP, DNS, HTTP/HTTPS, VPN, Firewalls, IDS/IPS, WAF, and email security.
- Experience in threat hunting, malware analysis, digital forensics, IOC analysis, and MITRE ATT&CK framework.
- Familiarity with SOAR platforms, vulnerability management, and cloud security (Azure, AWS, or GCP).
- Knowledge of scripting using PowerShell, Python, or Bash is an added advantage.
Preferred Certifications
- CEH (Certified Ethical Hacker)
- CompTIA Security+
- Microsoft SC-200: Security Operations Analyst
- Microsoft SC-100: Cybersecurity Architect (Preferred)
- GIAC GCIA, GCIH, or GCFA (Preferred)
- Splunk Certified Power User/Admin (Preferred)
- Microsoft Azure Security Engineer (AZ-500) – Preferred
Preferred Qualifications
- Bachelor's degree in Computer Science, Cyber Security, Information Technology, or a related field.
- Excellent analytical, problem-solving, communication, and documentation skills.
- Ability to work in a 24x7 SOC environment and lead critical incident response activities.
Work Location: In person