L2 SOC Analyst

UST

Bengaluru

On-site

INR 1,400,000 - 2,200,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

UST is seeking an experienced Incident Response Analyst in Bengaluru to lead detection, triage, and investigation of security incidents. The role requires hands-on expertise in SIEM investigations, EDR triage, and threat hunting, with engagement across endpoints, identity, email, cloud, and network environments.

You will coordinate with SecOps, IAM, Cloud, and other technical teams, support remediation, and communicate findings to clients and stakeholders while working in a 24x7 shift rotation.

Qualifications

  • 5–9 years of experience in Security Operations, Incident Response, Threat Hunting, or Cyber Defense.
  • Experience with SIEM investigations and EDR triage is required.
  • Proficient in security log analysis and incident reporting.

Responsibilities

  • Monitor, triage, and investigate security incidents and events.
  • Correlate events across multiple data sources to determine scope and impact.
  • Support containment, remediation, and incident closure activities.
  • Coordinate with SecOps, IAM, Cloud, Network, and other teams.
  • Document investigation notes, timelines, and reports clearly.

Skills

SIEM Platform
EDR Platform
MITRE ATT&CK
Log Analysis
Query languages (SPL/KQL/XQL)

Tools

Splunk
Microsoft Sentinel
Cortex XSIAM
Microsoft Defender for Endpoint
CrowdStrike Falcon
Cortex XDR

Job description

Role Description

Job Description Incident Response Analyst Experience 5–9 years in Security Operations, Incident Response, Threat Hunting, or Cyber Defense Shift 24×7 Rotational (including weekends and public holidays) Role Overview We are seeking an experienced Incident Response Analyst with strong hands-on knowledge of SIEM investigations, EDR triage, advanced email security analysis, incident response, threat hunting, and security log analysis. The candidate will be responsible for investigating security incidents, coordinating with internal security teams, supporting remediation activities, and communicating findings to clients and stakeholders.

  • Monitor, triage, and investigate security s and incidents.
  • Perform detailed incident analysis across endpoints, identity, email, cloud, and network environments.
  • Correlate security events across multiple tools and data sources.
  • Determine incident scope, severity, impact, and root cause.
  • Support containment, remediation, recovery, and incident closure activities.
  • Conduct proactive threat hunting and identify suspicious activity.
  • Coordinate with SecOps, IAM, Cloud, Network, Infrastructure, and other technical teams.
  • Maintain accurate investigation notes, incident timelines, and reports.
  • Recommend improvements to security detections, response playbooks, and operational processes.
  • Communicate investigation findings and recommendations to clients and stakeholders.
  • Ensure proper handover of open incidents across shifts.
  • Mandatory Skills SIEM Platform
  • Splunk
  • Microsoft Sentinel
  • Cortex XSIAM is most prioritized The candidate should have experience in:
  • Writing and modifying SPL / KQL / XQL queries
  • Investigating s and incidents
  • Correlating events across multiple log sources
  • Analyzing endpoint, identity, cloud, network, and authentication logs
  • Identifying true positives, false positives, and suspicious activity
  • Mandatory Skills EDR Platform
  • Microsoft Defender for Endpoint
  • CrowdStrike Falcon
  • Cortex XDR is most prioritized
  • Strong incident documentation and reporting skills
  • Preferred Skills Experience with the following technologies is preferred:
  • Cortex XSIAM
  • Cortex XDR
  • Proofpoint Email Security
  • Proofpoint TAP
  • Proofpoint TRAP
  • Microsoft Defender XDR Core Technical Skills — Mandatory Strong hands-on experience in security incident triage, investigation, containment, remediation, recovery, and closure.
  • Advanced endpoint investigation skills, including process-tree, command-line, file, hash, registry, persistence, network-connection, and EDR telemetry analysis.
  • Advanced email security investigation experience covering phishing, Business Email Compromise, email headers, sender infrastructure, malicious URLs, attachments.
  • Ability to independently investigate malware, account compromise, endpoint compromise, identity attacks, cloud security incidents, and potential data exfiltration.
  • Strong log analysis and event-correlation skills across endpoint, identity, email, cloud, authentication, network, DNS, proxy, VPN, and firewall telemetry.
  • Hands‑on threat hunting experience, including hypothesis‑driven hunts, attacker‑behavior analysis, and MITRE ATT&CK mapping.
  • Strong experience coordinating incident response and remediation activities with SecOps, IAM, Cloud, Network, Infrastructure, and other technical teams.
  • Soft Skills
  • Strong written and verbal communication skills
  • Good client‑facing and stakeholder-management skills
  • Ability to explain technical findings clearly
  • Strong analytical and problem‑solving capability
  • Ability to manage multiple incidents and priorities
  • Strong documentation and report‑writing skills
  • Ability to work independently and take ownership
  • Effective collaboration with cross‑functional teams
  • Ability to work under pressure during critical incidents
  • Strong shift‑handover and incident‑communication skills
  • Certifications — Preferred Industry‑recognized certifications in Security Operations, Incident Response, Digital Forensics, or Threat Hunting are preferred, such as GCIH, GCFA, SC‑200, CySA+, ECIH, or equivalent. Relevant hands‑on SOC and Incident Response experience will be given greater consideration than certifications alone.
Skills
  • SIEM
  • Splunk
  • MITRE ATT&CK
  • Log Analysis
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst - L2
Security Analyst - L2

Nopal Cyber, LLC. • Hyderabad

On-site
INR 1,200,000 - 1,600,000
Soc Analyst
Soc Analyst

Incedo • Gurugram District

On-site
INR 1,800,000 - 2,400,000
24x7 Rotational Shift
Willingness to work on weekends/holid-
Sr SOC Analyst - CyberAxis
Sr SOC Analyst - CyberAxis

Cyberaxislabs • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Soc Analyst
Soc Analyst

Deloitte Shared Services India • Mumbai

On-site
INR 900,000 - 1,500,000
SOC L3 Expert
SOC L3 Expert

Maandag® Middle East • India

On-site
INR 800,000 - 1,200,000
Cyber Security Analyst (SOC)
Cyber Security Analyst (SOC)

Genpact • Pune District

On-site
INR 900,000 - 1,500,000
Associate SOC
Associate SOC

Publicis Groupe • Gurgaon

On-site
INR 1,200,000 - 2,400,000
Associate SOC
Associate SOC

Publicis Groupe ANZ • Gurgaon

On-site
INR 1,400,000 - 2,200,000
Junior Engineer
Junior Engineer

Lyric Exponentials India Private Limited • Hyderabad

Hybrid
INR 1,000,000 - 1,500,000
Sr. Security Operations Analyst
Sr. Security Operations Analyst

Simfluent • Dadri

On-site
INR 1,200,000 - 1,800,000