The SOC Analyst will be responsible for continuous monitoring, detection, analysis, and initial response to security events using SIEM platforms and CrowdStrike Falcon EDR. The role focuses on alert triage, endpoint security analysis, incident escalation, and supporting threat detection and response operations while adhering to defined SOC processes and SLAs.
1. For CrowdStrike Falcon EDR Operations administrator: -
a. Monitor CrowdStrike Falcon console for endpoint detections and behavioural alerts.
b. Analyse:
i. Process execution trees
ii. Command-line arguments,
iii. File hashes.
iv. Network connections.
2. Perform response actions based on SOP:
I. Endpoint containment/isolation
ii. File quarantine.
iii. IOC blocking.
3. Assist in post-incident remediation and recovery
4. Technical Skills Required: -
SIEM
a) Hands-on experience with at least one SIEM platform:
b) Splunk / QRadar / ArcSight/any other
c) Strong understanding of:
i. Log sources and event normalisation
ii. Alert tuning and rule logic
iii. Correlation and use-case analysis
Endpoint Security
d) Hands-on experience with CrowdStrike Falcon EDR
e) Understanding of:
· Endpoint attack techniques
Persistence mechanisms
· Lateral movement indicators
f) Familiarity with Windows event logs and endpoint telemetry.
Pay: From ₹35,000.00 per month
Benefits:
- Flexible schedule
- Health insurance
- Provident Fund
Work Location: In person