We are seeking a skilled and proactive Security Analyst with strong expertise in Security Operations, Threat Detection, Incident Response, and Threat Hunting. The ideal candidate will have hands-on experience monitoring enterprise SIEM/SOAR platforms, tuning detection logic, investigating security incidents, and hunting for complex threats. A background in core network engineering and security infrastructure management is highly valued.
Key Responsibilities
- Incident Response & Triage: Investigate and triage high-volume security incidents (phishing, malware, credential compromise, insider threats) within strict SLAs, driving rapid containment and MTTR reduction.
- SIEM & Detection Engineering: Develop, tune, and maintain correlation rules, detection use cases, and custom search queries (KQL/XQL) across SIEM platforms to eliminate false positives and expand MITRE ATT&CK coverage.
- Threat Hunting & Intelligence: Conduct proactive hypothesis-driven and IOC-based threat hunting using MITRE ATT&CK frameworks and threat intelligence sources.
- SOAR & Automation: Design, build, and optimize automated playbooks and enrichment workflows to streamline SOC operations.
- Vulnerability & Exposure Management: Integrate vulnerability management findings (e.g., Tenable) with SIEM workflows to enable risk-based prioritization and accelerated remediation.
- SOC Enhancement & Infrastructure: Support log-source onboarding, Zero Trust monitoring, and security control optimization across endpoint, network, cloud, and email environments.
- Network & Security Collaboration: Leverage foundational Layer 2/Layer 3 networking knowledge (routing, switching, firewalls, VPNs) to troubleshoot and analyze complex network-level threat vectors.
Qualifications & Requirements
- Experience: 3–5 years of hands-on experience in SOC Operations, Incident Response, or Network Security engineering.
- Education: Bachelor’s degree in Technology (Computer Science, Information Technology, or relevant field).
Technical Skills
- SIEM / XDR: Proficiency in Microsoft Sentinel, Cortex XSIAM, Splunk, Securonix, or ArcSight.
- EDR / Endpoint: Experience with CrowdStrike Falcon, Microsoft 365 Defender, or SentinelOne.
- Email Security & Sandboxing: Hands-on with Proofpoint, Mimecast, Abnormal Security, Defender for Office 365, or ANY.RUN.
- Networking & Firewalls: Familiarity with Cisco, Juniper, Palo Alto (Panorama), FortiGate NGFWs, VPNs (IPSec/SSL), and Layer 2/Layer 3 troubleshooting.
- Threat Intelligence & DLP: Exposure to Anomali ThreatStream, Group-IB, Microsoft Purview, or Symantec DLP.
- Languages & OS: Strong query writing skills (KQL/XQL) and proficiency in Windows and Linux environments.
Pay: ₹278,576.08 - ₹1,067,556.38 per year
Benefits:
- Cell phone reimbursement
- Commuter assistance
- Paid sick time
- Provident Fund
Experience:
Work Location: Hybrid remote in Hyderabad, Telangana (Hyderabad, Hyderabad District)