Senior Level - SOC Detection Analyst
| Detailed JD (Roles and Responsibilities) | Responsibilities: |
| Advanced Security Event Analysis and Triage: | |
| Conduct in-depth analysis of complex and escalated security alerts and events from various security tools (SIEM, IDS/IPS, EDR, etc.). | |
| Correlate data from multiple sources to identify and validate potential security incidents with high accuracy. | |
| Perform advanced triage to determine the scope, severity, and potential impact of security events. | |
| Document analysis findings clearly and concisely, providing actionable intelligence for incident response. | |
| Detection Rule Development and Optimization: | |
| Develop, implement, and fine-tune correlation rules, alerts, and dashboards within the SIEM platform to improve detection capabilities and reduce false positives. | |
| Analyze existing detection logic and recommend improvements based on threat intelligence, incident trends, and best practices. | |
| Stay current with emerging threats and attack techniques to proactively develop new detection strategies. | |
| Threat Intelligence Integration: | |
| Leverage threat intelligence feeds and platforms to enrich security event analysis and identify potential threats targeting the organization. | |
| Correlate threat intelligence with internal security data to proactively identify indicators of compromise (IOCs). | |
| Contribute to the development of threat profiles and attack scenarios relevant to the organization. | |
| Incident Escalation and Collaboration: | |
| Serve as a point of escalation for complex or high-severity security events. | |
| Collaborate effectively with incident responders, threat hunters, and other security teams to provide critical context and analysis during incident handling. | |
| Provide technical guidance and support to junior analysts during incident triage and analysis. | |
| Security Tooling and Technology Expertise: | |
| Maintain a strong understanding of the organization's security infrastructure and the capabilities of various security tools. | |
| Troubleshoot issues with security monitoring tools and contribute to their optimization. | |
| Evaluate and recommend new security technologies or enhancements to existing tools to improve detection capabilities. | |
| Development of Knowledge and Procedures: | |
| Contribute to the development and maintenance of SOC knowledge base articles, standard operating procedures (SOPs), and playbooks related to detection and analysis. | |
| Share knowledge and best practices with other SOC analysts through training and mentorship. | |
| Proactive Threat Hunting Support: | |
| Collaborate with threat hunters by providing insights from security event analysis and identifying potential areas of focus for proactive investigations. | |
| Assist in the development and execution of threat hunting methodologies. | |
| Reporting and Metrics: | |
| Contribute to the development of key performance indicators (KPIs) and metrics related to detection effectiveness. | |
| Prepare reports on detection trends, alert volumes, and analysis findings. | |
|
| |
| Mandatory skills |
|
| Desired/ Secondary skills |
|
| Domain |
|
| Max Vendor Rate in Per Day (Currency in relevance to work location) | 11000 INR / Day |
| Work Location given in ECMS ID | PUNE / Chennai preferable |
| WFO/WFH/Hybrid WFO | Hybrid WFO |