Security Analyst

Access Healthcare

Zone 7 Ambattur

On-site

INR 1,200,000 - 2,100,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Access Healthcare seeks an experienced Security Analyst (Tier 2) to join its SOC team. You will expertly monitor, investigate, and respond to cybersecurity incidents across a large enterprise, ensuring robust detection, triage, and remediation.

Responsibilities include managing SIEM, coordinating Tier 2 IR activities, documenting investigations, performing RCA, and enhancing detection rules and dashboards aligned to MITRE ATT&CK. Collaboration with IT and infra teams is required.

Qualifications

  • Degree in information technology with Cyber Security/Forensic focus.
  • 5-7 years of experience in a 24x7 SOC environment.
  • Hands-on with SIEM tools (Splunk, Sentinel, QRadar) and EDR (CrowdStrike, Defender, SentinelOne, Cortex XDR).
  • Relevant certifications such as CEH, CHFI, CompTIA+, GCIA, GCIH, Splunk, Elastic, Microsoft Sentinel, QRadar.

Responsibilities

  • Manage and maintain the SIEM platform, ensuring log ingestion health, data source onboarding, parser validation, and rule accuracy.
  • Lead and coordinate Tier 2 incident response activities per the SOC IR playbook and SLAs.
  • Document investigation steps, evidence, and actions in the ITSM/ticketing system (ServiceNow, Jira).
  • Perform root cause analysis (RCA) on significant incidents and contribute to post-incident reviews.
  • Develop, tune, and maintain detection and correlation rules and dashboards within MITRE ATT&CK framework.
  • Identify log source gaps and onboard missing data sources with IT/infrastructure teams.
  • Automate triage tasks through SOAR playbooks (Cortex XSOAR, Sentinel Logic Apps).
  • Monitor and investigate endpoint telemetry using EDR: CrowdStrike, Defender, SentinelOne, Cortex XDR.
  • Analyze firewall logs and network traffic from Palo Alto, FortiGate, Cisco ASA, Check Point.
  • Investigate IDS/IPS, web proxy, DNS security, and NDR alerts.
  • Consume threat intel feeds, triage IOCs, enrich alerts, update blocks across SIEM/firewall/EDR.
  • Track active threat campaigns and CVEs relevant to the organization.
  • Collaborate with IT/engineering teams on threat remediation.

Skills

SIEM tools
EDR platforms
Incident response
SOAR automation
Threat intel
Network analysis

Education

Degree in Cyber Security/Forensic/IT

Tools

Splunk
Microsoft Sentinel
QRadar
CrowdStrike Falcon
Microsoft Defender
SentinelOne
Cortex XDR

Job description

Job description

Greetings from Access Healthcare!!!

Role

We are seeking an experienced Security Analyst (Tier 2) to join our Security Operations Center (SOC) team. The successful candidate will serve as a subject matter expert in enterprise security monitoring, responsible for the detection, investigation, and response to cybersecurity incidents and threats across a large-scale, complex enterprise environment.

Responsibilities
  • Manage and maintain the SIEM platform ensuring log ingestion health, data source onboarding, parser validation, and rule accuracy.
  • Lead and coordinate Tier 2 incident response activities containing, eradicating, and recovering from security incidents in line with the SOC IR playbook and defined SLAs.
  • Document all investigation steps, findings, evidence, and actions taken accurately within the ITSM / ticketing system (e.g. ServiceNow, Jira).
  • Perform root cause analysis (RCA) on significant incidents and contribute lessons learned to post-incident review reports.
  • Develop, tune, and maintain detection rules, correlation rules, and dashboards to improve coverage across the MITRE ATT&CK framework.
  • Identify log source gaps and work with IT and infrastructure teams to onboard missing data sources into the SIEM.
  • Automate repetitive triage tasks through SOAR playbooks (e.g. Cortex XSOAR, Sentinel Logic Apps) to improve analyst efficiency and reduce MTTD/MTTR.
  • Monitor and investigate endpoint telemetry using EDR platforms (e.g. CrowdStrike Falcon, Microsoft Defender for Endpoint, Sentinel One) to detect malicious activity including malware, ransomware, and living[1]off-the-land (LotL) attacks.
  • Analyse firewall logs and network traffic data (Palo Alto, FortiGate, Cisco ASA, Check Point) to identify suspicious traffic patterns, policy violations, and network-based threats.
  • Investigate alerts originating from IDS/IPS systems, web proxies, DNS security platforms, and network detection and response (NDR) solutions.

Consume and operationalize threat intelligence feeds (commercial and open-source) triaging IOCs, enriching alerts, and updating blocking lists in SIEM, firewall, and EDR platforms.

  • Track active threat campaigns, adversary groups, and CVEs relevant to the organization’s sector and technology stack.
  • Collaborate with IT, infrastructure, and engineering teams on threat remediation.
Qualification
  • Any degree in information technology specialization in Cyber Security/ Forensic, computer science, Information Technology
  • 5-7 years of experience working in a 24x7 Security Operation Center (SOC) environment.
  • Hands-on experience working with any of the SIEM tools (Splunk, Microsoft Sentinel, or QRadar) • EDR expertise (CrowdStrike Falcon, Microsoft Defender, SentinelOne, or Cortex XDR)
  • Relevant certifications such as CEH, CHFI, COMPTIA +,GCIA, GCIH, Splunk, Elastic, Microsoft Sentinel, QRadar, or equivalent.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst
SOC Analyst

Access Healthcare • Chennai District

On-site
INR 900,000 - 1,300,000
Cyber Security Analyst (SOC)
Cyber Security Analyst (SOC)

Genpact • Pune District

On-site
INR 900,000 - 1,500,000
Sr. Security Operations Analyst
Sr. Security Operations Analyst

Simfluent • Dadri

On-site
INR 1,200,000 - 1,800,000
E2E Networks - Security Operations Center Analyst - Firewall Management
E2E Networks - Security Operations Center Analyst - Firewall Management

E2E Cloud • Chennai District

On-site
INR 500,000 - 800,000
Security Analyst - L2
Security Analyst - L2

Nopal Cyber, LLC. • Hyderabad

On-site
INR 1,200,000 - 1,600,000
Cyber Security Engineer II
Cyber Security Engineer II

HighRadius • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Walk-in | Senior Security Analyst
Walk-in | Senior Security Analyst

Access Healthcare • Chennai District

On-site
INR 900,000 - 1,200,000
Security Operations Center Analyst - L2 || Mumbai || Only Immediate Joiner
Security Operations Center Analyst - L2 || Mumbai || Only Immediate Joiner

Innova ESI • Mumbai

On-site
INR 800,000 - 1,200,000
Cyber Security Engineer II
Cyber Security Engineer II

high radius • Hyderabad

On-site
INR 900,000 - 1,500,000
Senior Security Analyst
Senior Security Analyst

UltraViolet Cyber • Hyderabad

On-site
INR 800,000 - 1,200,000