Security Operations Center Analyst - L2 || Mumbai || Only Immediate Joiner
Innova ESI
Mumbai
On-site
INR 800,000 - 1,200,000
Full time
14 days+
Application generator
A complete application in a minute — tailored resume and cover letter, ready to send.
Get past ATS filters
Job summary
A cybersecurity firm located in Mumbai is seeking an experienced Security Operations Center (SOC) Analyst to perform real-time security monitoring, incident response, and threat hunting. The ideal candidate will have at least 4 years of SOC experience, proficiency with SIEM tools like Splunk and IBM QRadar, and a strong understanding of network security. Additional responsibilities include mentoring junior analysts and contributing to security assessments. This role offers opportunities for professional growth in a dynamic environment.
Qualifications
4+ years of total IT/security experience, with a minimum of 4+ years in SOC operations.
Strong understanding of network protocols, firewalls, proxies, endpoint security, and malware analysis.
Familiarity with MITRE ATT&CK framework, NIST, and ISO 27001 standards.
Responsibilities
Perform real-time security monitoring and incident response.
Investigate security alerts and correlate events using SIEM tools.
Manage the incident response lifecycle.
Skills
Real-time security monitoring
Incident response
SIEM tools
Threat hunting
Log analysis
Mentorship
Analytical thinking
Education
Bachelor’s degree in Computer Science, Information Security, or related discipline
Tools
Splunk
IBM QRadar
ArcSight
Azure Sentinel
CrowdStrike
Carbon Black
SentinelOne
Job description
Perform real-time security monitoring, analysis, and incident response for enterprise systems, networks, and applications.
Investigate security alerts and correlate events using SIEM tools (e.g., Splunk, QRadar, ArcSight, Azure Sentinel).
Conduct threat hunting, log analysis, and root cause investigations for potential or actual incidents.
Manage the incident response lifecycle — triage, containment, eradication, recovery, and post-incident review.
Escalate incidents to higher levels (L3 or CSIRT) as per defined playbooks.
Develop and tune correlation rules, dashboards, and detection use cases.
Collaborate with IT, network, and application teams to mitigate vulnerabilities.
Generate incident reports, maintain SOC documentation, and contribute to process improvements.
Participate in security assessments, vulnerability management, and threat intelligence integration.
Mentor junior analysts (L1/L2) and help strengthen SOC operational maturity.
<\/ul>
Required Skills and Qualifications:
Bachelor’s degree in Computer Science, Information Security, or related discipline.
4+ years of total IT/security experience, with minimum 4+ years in SOC operations.
Proficient in SIEM platforms such as Splunk, IBM QRadar, ArcSight, or Azure Sentinel.
Strong understanding of network protocols, firewalls, proxies, endpoint security, and malware analysis.
Expertise in incident response, log analysis, and threat intelligence correlation.
Familiarity with MITRE ATT&CK framework, NIST, and ISO 27001 standards.
Experience with EDR tools (CrowdStrike, Carbon Black, SentinelOne, etc.).
Knowledge of Windows, Linux, and cloud security (AWS, Azure) environments.
Excellent analytical thinking, documentation, and communication skills.