Lead SOC Analyst

Sampoorna Consultants

Bengaluru

On-site

INR 1,000,000 - 1,500,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Sampoorna Consultants is seeking a Lead SOC Analyst to own incident response and threat monitoring across systems. You will triage, investigate, contain and remediate high-severity incidents while guiding junior staff and coordinating with global SOC teams.

You’ll also refine detections and contribute to playbooks and forensic investigations. The ideal candidate has strong SIEM/EDR experience, scripting skills, and familiarity with MITRE ATT&CK, NIST CSF, and security workflows.

Qualifications

  • Experience in a SOC, incident response or cybersecurity investigation role.
  • Ability to analyse security alerts and logs across SIEM, EDR, cloud, identity and network security tools.
  • Experience with scripting or automation (e.g. Python, PowerShell).
  • Familiarity with MITRE ATT&CK, NIST CSF, or equivalent.
  • Strong written and verbal communication, able to explain technical findings clearly.
  • Ability to work effectively under pressure during incident scenarios.

Responsibilities

  • Perform triage, investigation, containment, and remediation for complex incidents.
  • Act as senior escalation point and guide analysts during incident handling.
  • Contribute to incident bridges with clear technical updates and findings.
  • Collect and analyze forensic data across endpoints, network, cloud and identity sources.
  • Create incident timelines, investigation notes, and post-incident summaries.
  • Support post-incident reviews with technical insights and lessons learned.
  • Review alerts from SIEM/EDR/cloud security and tune detection rules.
  • Conduct threat-hunting activities under defined hypotheses.
  • Support SOC tooling, automation, and playbooks improvements.

Skills

SOC experience
Incident response
Threat hunting
Log analysis
Python/PowerShell
MITRE ATT&CK
Communication
Under pressure

Tools

EDR tooling
SOAR
Forensic tooling

Job description

Lead SOC Analyst - AM - BLR / GGN - J50820
Role & responsibilities
Core Responsibilities
Incident Response & Investigation
  • Perform triage, investigation, containment, and remediation activities for complex and high-severity cybersecurity incidents.
  • Act as a senior technical escalation point during incident handling, providing guidance and direction to analysts as required.
  • Participate in incident bridges, contributing clear technical updates and investigative findings.
  • Conduct forensic data collection and analysis across endpoints, network, cloud, and identity sources.
  • Produce accurate and well-structured incident timelines, investigation notes, and post-incident summaries.
  • Support post-incident reviews by contributing technical insights and lessons learned.
Detection & Threat Monitoring
  • Review and investigate alerts generated from SIEM, EDR, cloud security, and identity platforms.
  • Support the tuning and refinement of detection rules to improve alert quality and reduce false positives.
  • Conduct threat-hunting activities under defined hypotheses, using available telemetry and analytical techniques.
  • Identify gaps in visibility or logging and raise these with senior analysts or engineering teams.
SOC Tooling & Automation Support
  • Use SOC tooling effectively to support investigations and response activities.
  • Contribute ideas and feedback to improve SOC workflows, automation and playbooks.
  • Assist with the validation and testing of changes to SOC tools and automated response processes.
  • Highlight tooling issues or limitations that impact investigation effectiveness.
Governance, Process & Assurance Support
  • Support internal and external audit activities by providing investigation evidence and technical input when requested.
  • Follow established SOC procedures and ensure investigations are documented accurately and consistently.
  • Contribute to the maintenance of SOC documentation, playbooks and operational procedures.
  • Participate in lessons-learned activities and contribute suggestions for process improvement.
Team & Stakeholder Interaction
  • Provide informal guidance and support to junior analysts during investigations, helping to improve analysis quality.
  • Share technical knowledge and investigative techniques with peers through day-to-day collaboration.
  • Communicate technical findings clearly to SOC leads and relevant stakeholders during incidents.
  • Work collaboratively with Legal, Risk, Privacy, Crisis Management and Global SOC teams when required.
Operational Support
  • Support daily SOC monitoring activities during periods of increased workload or incident activity.
  • Assist with escalation handling for complex alerts or investigations.
  • Maintain a high standard of investigative quality and professional conduct during operational activity.
Required Skills & Experience
  • Experience working in a SOC, incident response or cybersecurity investigation role.
  • Strong understanding of common attack techniques, threat actor behaviours, and investigative methodologies.
  • Ability to analyse security alerts and logs across SIEM, EDR, cloud, identity and network security tools.
  • Experience with scripting or automation (e.g. Python, PowerShell) is advantageous.
  • Familiarity with frameworks such as MITRE ATT&CK, NIST CSF, or equivalent.
  • Strong written and verbal communication skills, with the ability to explain technical findings clearly.
  • Ability to work effectively under pressure during incident scenarios.
Preferred Qualifications
  • Relevant industry certifications such as CompTIA CySA+ or Microsoft Certified:
  • Security Operations Analyst Associate (SC-200).
  • Hands-on experience with EDR, SOAR, or forensic tooling.
  • Experience participating in threat-hunting activities or security exercises.
  • Exposure to tabletop or incident-response simulations.
  • Certifications or demonstrated expertise in Microsoft security technologies related to Sentinel, Purview, or Microsoft Defender suites (e.g., Microsoft Certified: Information Protection Administrator Associate (SC-400), Microsoft Certified: Azure Security Engineer Associate (AZ-500)).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Team Lead - SOC
Team Lead - SOC

Indian Financial Technology And Alliedservices • Hyderabad

On-site
INR 1,800,000 - 2,500,000
SOC L3 Expert
SOC L3 Expert

Maandag® Middle East • India

On-site
INR 800,000 - 1,200,000
Senior SOC Analyst/SOC Lead
Senior SOC Analyst/SOC Lead

NTT DATA BUSINESS SOLUTIONS • Hyderabad

Hybrid
INR 1,200,000 - 2,400,000
SOC-Associate Director
SOC-Associate Director

SISA • Bengaluru

On-site
INR 1,000,000 - 1,500,000
L3 SOC Analyst
L3 SOC Analyst

UST • Bengaluru

On-site
INR 1,500,000 - 2,100,000
SOC L1 Analyst
SOC L1 Analyst

Verint • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Information Security Specialist
Information Security Specialist

ZEISS India • Bengaluru

On-site
INR 800,000 - 1,200,000
Senior Associate L2- SOC Analyst
Senior Associate L2- SOC Analyst

Publicis Groupe • Gurgaon

On-site
INR 1,200,000 - 2,500,000
Senior Associate L2- SOC Analyst
Senior Associate L2- SOC Analyst

Publicis Groupe Holdings B.V • Gurugram District

On-site
INR 2,500,000 - 4,500,000
Senior Associate L2- SOC Analyst
Senior Associate L2- SOC Analyst

Publicis Groupe ANZ • Gurgaon

On-site
INR 1,500,000 - 2,100,000