Job Description
Bharat Datacenter is hiring an experienced SOC L2 Engineer with strong expertise in Network Security, DDoS Detection & Mitigation, BGP, Traffic Analysis, and Incident Response.
The ideal candidate should have hands-on experience working with network traffic, security incidents, DDoS attacks, firewalls, packet analysis, and monitoring tools. This role involves working on real-time cloud, VPS, data center, and Internet-facing infrastructure.
Roles & Responsibilities
- Monitor and investigate security events, network alerts, and abnormal traffic patterns.
- Detect, analyze, and mitigate DDoS attacks.
- Analyze attack types such as UDP floods, TCP SYN floods, ICMP floods, DNS/NTP amplification, HTTP/HTTPS floods, and application-layer attacks.
- Investigate attack sources, destinations, protocols, ports, packet rates, bandwidth utilization, and traffic patterns.
- Execute DDoS mitigation procedures using ACLs, rate limiting, BGP diversion, RTBH, BGP FlowSpec, traffic filtering, and scrubbing platforms.
- Monitor mitigation effectiveness and minimize the impact on legitimate customer traffic.
- Perform packet-level analysis using Wireshark, tcpdump, and tshark.
- Analyze NetFlow, sFlow, and IPFIX data.
- Investigate BGP routing, route advertisements, route changes, and Internet traffic paths.
- Monitor and troubleshoot firewalls and DDoS protection infrastructure.
- Handle L2 security incidents escalated by SOC L1 and NOC teams.
- Perform root-cause analysis and identify attack vectors and customer impact.
- Investigate alerts from monitoring and security platforms.
- Coordinate with Network Engineering, NOC, Infrastructure, Security teams, customers, and upstream providers during incidents.
- Prepare incident reports, technical documentation, and DDoS mitigation reports.
- Ensure proper incident escalation and shift handover.
Required Skills
- Strong understanding of TCP/IP networking.
- Good knowledge of IPv4/IPv6, VLANs, Routing, NAT, and DNS.
- Strong understanding of BGP and Internet Routing.
- Hands-on experience with DDoS detection, analysis, and mitigation.
- Knowledge of UDP, TCP SYN, ICMP, DNS amplification, and application-layer attacks.
- Experience with BGP FlowSpec, RTBH, ACLs, rate limiting, and traffic filtering.
- Hands-on experience with packet analysis tools such as Wireshark, tcpdump, and tshark.
- Experience with NetFlow, sFlow, or IPFIX.
- Good Linux troubleshooting and command-line skills.
- Experience with firewall technologies and security monitoring tools.
- Ability to analyze network traffic, packet captures, firewall logs, flow records, and security alerts.
- Strong troubleshooting, analytical, and incident response skills.
Preferred Skills
Candidates with experience in any of the following will be preferred:
- FortiGate / FortiOS
- Palo Alto Networks
- MikroTik
- Cisco
- Juniper
- Arista
- NETSCOUT Arbor
- Radware
- Cloudflare
- Akamai
- DDoS Scrubbing Platforms
- Zabbix
- Grafana
- Prometheus
- Wazuh
- Elastic / ELK
- Splunk
- Microsoft Sentinel
- Python or Bash scripting
- Network or Security Automation
- REST APIs
Preferred Experience
Candidates with experience in any of the following environments will be preferred:
- SOC
- NOC
- Network Security Operations
- ISP
- Cloud Service Provider
- Data Center
- DDoS Operations
Candidate Requirements
- 2–5 years of relevant experience in SOC, NOC, Network Security, DDoS Operations, ISP, Cloud, or Data Center environments.
- Strong practical experience in networking and DDoS mitigation.
- Ability to work effectively during high-severity and time-critical security incidents.
- Good communication and technical documentation skills.
- Willingness to work in a 24×7 rotational shift environment.
Pay: Up to ₹1,000,000.00 per year
Work Location: In person