Intrusion Analyst III

Jobtailor

Bengaluru

Hybrid

INR 1,800,000 - 2,800,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor seeks an experienced SOC engineer to monitor and respond to cyber events across on‑prem and cloud environments. You will investigate endpoints, networks, emails, identities, and cloud telemetry, correlate evidence, and drive remediation with structured playbooks and automation.

You will work with global teams, implement detection improvements, develop security queries and scripts, and help operationalize AI-assisted investigations using Copilot/ChatGPT/Gemini.

Qualifications

  • 4–6 years of SOC/cybersecurity operations experience.
  • Hands-on experience with EDR and SIEM across on‑prem and cloud.
  • Experience with SOAR, email security, incident/case management, firewall, IPS, and detection use‑case development.

Responsibilities

  • Monitor, triage, analyze, and support remediation of cyber events using SOC procedures and playbooks.
  • Investigate telemetry across endpoints, networks, emails, identities, cloud, Windows and Linux.
  • Correlate evidence to determine scope, impact, root cause, and recommended actions.

Skills

SOC Operations
EDR & SIEM
AI/GenAI tool proficiency
Incident Management
Security Query Development

Education

Bachelor’s degree in CS/IT/Engineering
Master’s degree (preferred)
Certifications: Security+, CISSP, CCSP, GIAC

Tools

EDR
SIEM
SOAR
Copilot/ChatGPT/Gemini
Cloud Security Tooling

Job description

  • Monitor, triage, analyze, investigate, and support remediation of cyber events using SOC procedures, playbooks, escalation paths, and service expectations
  • Investigate endpoint, network, email, identity, cloud, Windows, and Linux telemetry
  • Correlate evidence to determine scope, impact, root cause, and recommended actions
  • Run approved commands, queries, scripts, and automation while maintaining operational controls and documentation
  • Identify indicators of compromise, suspicious behaviors, attack patterns, and emerging risks
  • Escalate confirmed or high-risk incidents to appropriate response teams
  • Communicate status, findings, risk context, and recommended next steps to technical and business stakeholders
  • Improve alert logic, correlation rules, detection use cases, thresholds, enrichment, prioritization, and false-positive suppression
  • Partner with engineering and platform teams to operationalize detection improvements across SIEM, EDR, SOAR, email security, firewall, IPS, and cloud security tooling
  • Use approved AI/GenAI capabilities to support investigation summarization, evidence correlation, query/script drafting, threat-context synthesis, case documentation, and recommendations
  • Validate AI-generated analysis against authoritative telemetry and security evidence
  • Assess AI-assisted investigation quality and provide structured feedback
  • Develop prompts, workflows, evaluation criteria, test cases, and feedback loops for AI-assisted SOC analysis
  • Support cybersecurity solution reviews, technology research, supplier/product evaluations, and operational documentation
  • Create and review case notes, SOPs, playbooks, knowledge articles, metrics, reports, and presentations
  • Participate in team assignments, projects, meetings, technical discussions, and cross-functional initiatives
  • Protect sensitive information and operate according to company policies, security standards, ethics, and compliance requirements
Requirements
  • B.E./B.Tech/M.S./M.Tech/MCA or equivalent technical qualification
  • Approximately 4–6 years of relevant SOC/cybersecurity operations experience
  • Hands-on experience with EDR and SIEM technologies across on-premises and cloud environments
  • Experience with SOAR, email security, incident/case management, firewall, IPS, security correlation, detection use-case development, and deployment
  • Cybersecurity investigation skills including malware analysis, phishing/email analysis, network and endpoint investigation, and Windows/Linux operating-system analysis
  • Practical exposure to Copilot, ChatGPT, Gemini, or equivalent AI/GenAI tools
  • Ability to develop or adapt security queries, scripts, and automation
  • Experience working with global teams
  • Flexibility to work rotational shifts as business needs require
  • Bachelor’s degree in computer science, information technology, engineering, information systems, cybersecurity or related area and 2 years’ experience in intrusion analysis or related area; or 4 years’ experience in intrusion analysis or related area
  • Preferred: Certification in Security+, Network+, GISF, CISA, CISSP, CCSP, or GCIH
  • Preferred: Master’s degree in a related field
Core Competencies

Demonstrates expertise in cybersecurity operations, including incident investigation, threat detection, and remediation using EDR and SIEM technologies. Proficient in leveraging AI/GenAI tools for analysis and automation while ensuring compliance with security standards and policies.

Highest-signal resume keywords
  • SOC Operations Experience
  • EDR and SIEM Technologies
  • Cybersecurity Investigation Skills
  • AI/GenAI Tool Proficiency
  • Incident Management
ATS Optimization Keywords
Hard Skills
  • Malware Analysis
  • Phishing/Email Analysis
  • Network Investigation
  • Endpoint Investigation
  • Windows/Linux Operating‑System Analysis
  • Security Query Development
  • Automation Scripting
  • Detection Use-Case Development
  • Incident Response
  • Threat Detection
Soft Skills
  • Communication
  • Collaboration
  • Flexibility
Certifications & Qualifications
  • Security+
  • Network+
  • GISF
  • CISA
  • CISSP
  • CCSP
  • GCIH
Industry Keywords
  • Cybersecurity
  • Incident Management
  • Threat Analysis
  • Operational Documentation
  • Compliance Requirements
Tools & Technologies
  • SOAR
  • Email Security
  • Firewall
  • IPS
  • Cloud Security Tooling
  • Copilot
  • ChatGPT
  • Gemini
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Security Operations Analyst
Sr. Security Operations Analyst

Simfluent • Dadri

On-site
INR 1,200,000 - 1,800,000
Soc Analyst
Soc Analyst

BUSINESSNEXT • Dadri

On-site
INR 1,200,000 - 2,000,000
SISA Information Security - Security Operations Center Manager - SIEM/SOAR
SISA Information Security - Security Operations Center Manager - SIEM/SOAR

SISA • Bengaluru

On-site
INR 3,000,000 - 5,200,000
Head - SOC Incident Response
Head - SOC Incident Response

Adani Enterprises Limited • Ahmedabad District

On-site
INR 2,200,000 - 4,500,000
SOC Manager
SOC Manager

SISA • Bengaluru

On-site
INR 6,000,000 - 9,000,000
Sr. Security Operations Analyst
Sr. Security Operations Analyst

ShyftLabs • Dadri

On-site
INR 1,500,000 - 2,600,000
ARCHITECT - SOC Monitoring
ARCHITECT - SOC Monitoring

Happiest Minds Technologies • Bengaluru

Hybrid
INR 4,500,000 - 7,500,000
Chief Analyst, Cyber Security Operations
Chief Analyst, Cyber Security Operations

SES S.A Brazil • Chennai District

On-site
INR 1,200,000 - 3,000,000
Cyber Sec_Firewall_SOC/SIEM_VAPT Experts
Cyber Sec_Firewall_SOC/SIEM_VAPT Experts

Infosys • Khordha

On-site
INR 900,000 - 1,400,000
SOC/SIEM Experts
SOC/SIEM Experts

Infosys • Bengaluru

On-site
INR 800,000 - 1,200,000