Job Summary: Experience Profile (3 Years SOC Analyst)
✔ 3+ years in SOC Monitoring & Incident Handling
✔ Hands-on Logpoint (GuardSIX) SIEM operations
✔ Experience in alert triage and incident investigation
✔ Knowledge of EDR, Firewall, IDS/IPS, Email Security logs
✔ Familiarity with MITRE ATT&CK and Threat Hunting
✔ Working experience in a 24x7 SOC environment
Location: Hyderabad
Shift: 24x7 Rotational Shifts
Work Location: 5 days work from office(we can discuss about Night shifts)
Key Responsibilities
Security Monitoring & Incident Detection (Must have)
- Monitor security events and alerts generated from Logpoint SIEM (GuardSIX) and integrated security tools.
- Perform real-time analysis of security incidents and suspicious activities.
- Investigate alerts related to malware, phishing, ransomware, insider threats, privilege misuse, and unauthorized access.
- Validate and triage security alerts based on severity and business impact.
- Escalate incidents to L2 & L3 teams and stakeholders as per defined procedures.
Incident Response & Investigation (Must Have)
- Conduct incident investigations using SIEM queries and threat intelligence sources.
- Analyze logs from:
o Windows Servers & Workstations
o Linux Systems
o Active Directory
o Firewalls
o IDS/IPS
o Proxy and Web Gateways
o EDR/XDR Solutions
o Cloud Platforms (Azure, AWS, GCP)
- Perform root cause analysis and incident documentation.
- Support containment, eradication, and recovery activities.
Threat Hunting & Threat Intelligence (Must have)
- Execute proactive threat hunting activities using Logpoint searches.
- Leverage MITRE ATT&CK framework for threat mapping.
- Analyze Indicators of Compromise (IoCs).
- Correlate threat intelligence feeds with internal security events.
- Identify anomalous user and system behaviors.
Logpoint SIEM Administration & Use Case Monitoring (Good to have)
- Create, modify, and tune Logpoint correlation rules and use cases.
- Fine-tune alert thresholds to reduce false positives.
- Develop dashboards, reports, and custom searches.
- Monitor log collection health and data ingestion.
- Validate parser functionality and troubleshoot log collection issues.
- Perform use case validation and testing.
Required Technical Skills
SIEM
- Hands-on experience with:
o Logpoint SIEM (GuardSIX) – Mandatory
O Experience With Splunk/QRadar/Microsoft Sentinel (Preferred)
Security Technologies
- Firewalls (Palo Alto, Fortinet, Check Point, Cisco)
- IDS/IPS (Snort, Suricata, Trend Micro)
- EDR/XDR (Microsoft Defender, CrowdStrike, SentinelOne)
- Email Security Solutions
- Web Proxy Solutions
- Vulnerability Management Tools
Operating Systems
- Windows Administration
- Linux Administration
Networking
- TCP/IP
- DNS
- DHCP
- VPN
- HTTP/HTTPS
- SMTP
- Network Security Concepts
Required Knowledge
- Cyber Kill Chain
- MITRE ATT&CK Framework
- Security Incident Response Lifecycle
- Threat Intelligence Concepts
- Malware Analysis Fundamentals
- Security Monitoring Best Practices
- SOC Processes and Procedures
- Event Correlation Techniques
Qualifications
- Bachelor's Degree in Computer Science, Information Security, IT, or related field.
- 3+ years of experience in SOC operations.
- Experience working in 24x7 rotational shifts.
- Strong analytical and troubleshooting skills.
- Excellent verbal and written communication skills.
Preferred Certifications
- CompTIA Security+
- CEH (Certified Ethical Hacker)
- SC-200 (Microsoft Security Operations Analyst)
- Logpoint Certified Analyst (Preferred)
Key Performance Indicators (KPIs)
- Incident Response SLA Compliance
- Mean Time to Detect (MTTD)
- Mean Time to Respond (MTTR)
- Alert Triage Accuracy
- Use Case Effectiveness
- Threat Hunt Outcomes
- Reduction in False Positive Alerts