Security Operations Engineer

UST

Mumbai

On-site

INR 900,000 - 1,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

UST is seeking a Security Operations Engineer - L1 in Mumbai to join our cybersecurity operations team. The role demands 4-5 years of enterprise security experience, strong networking and OS fundamentals, and solid knowledge of endpoint protection, SIEM, and incident response.

You will monitor security tools, triage incidents, and engage with infrastructure, network, and application teams to ensure rapid containment and resolution.

Qualifications

  • 4-5 years of experience in enterprise cybersecurity operations.
  • Strong foundation in networking, operating systems, endpoint security, security monitoring, and incident response.

Responsibilities

  • Monitor enterprise security tools and events in a 24x7 shift-based environment.
  • Respond to security events and tickets within defined SLA and procedures.
  • Perform initial triage, investigation, troubleshooting, and escalation of security incidents.
  • Analyze events across endpoint, network, email, identity, and cloud environments.
  • Coordinate with IT teams during incident investigation and resolution.
  • Update SOPs, runbooks, and knowledge articles.

Skills

Networking
Operating Systems
Endpoint security
Security monitoring
Incident response
Log analysis
SIEM
Change management
Ticketing
SOPs
Collaboration
24x7 shift

Tools

Defender for Endpoint
CrowdStrike
SentinelOne
Cortex XDR
EDR/XDR solutions

Job description

Security Operations Engineer

We are looking for a Security Operations Engineer - L1 with 4-5 years of experience in enterprise cybersecurity operations. The ideal candidate should have a strong foundation in networking, operating systems, endpoint security, security monitoring, and incident response.

The role will be responsible for 24x7 security monitoring, initial incident triage and investigation, security tool health monitoring, troubleshooting, ticket management, and escalation of complex incidents to L2/L3 teams. The candidate will work closely with infrastructure, network, server, application, and security teams to support timely resolution of security incidents and maintain the overall security posture of the organization.

Key Responsibilities
  • Monitor enterprise security tools and security events in a 24x7 shift-based environment.
  • Monitor and respond to security s and tickets within defined SLA and operational procedures.
  • Perform initial triage, investigation, troubleshooting, and escalation of security incidents.
  • Analyze security events across endpoint, network, email, identity, and cloud environments.
  • Investigate security incidents involving:
    • Malware and ransomware
    • Phishing and malicious emails
    • Suspicious logins and authentication activity
    • Unauthorized access
    • Endpoint security s
    • Indicators of Compromise (IOCs)
  • Perform basic log analysis and correlation using SIEM and other security monitoring platforms.
  • Conduct daily health checks and operational monitoring of security tools and identify issues requiring remediation.
  • Execute approved standard changes and operational activities in accordance with change management processes.
  • Create, update, and maintain security incident tickets with accurate investigation details, actions taken, and resolution information.
  • Maintain and update SOPs, operational runbooks, knowledge articles, and troubleshooting guides.
  • Coordinate with Network, Server, Infrastructure, Application, Cloud, IAM, and other IT teams during security incident investigation and resolution.
  • Escalate complex or high‑severity incidents to L2/L3 security teams with appropriate investigation details and evidence.
  • Support vulnerability remediation, endpoint compliance, and security hygiene activities.
  • Participate in shift handovers, incident reviews, knowledge‑sharing sessions, and continuous improvement initiatives.
  • Follow established security policies, procedures, and incident response processes.
Mandatory Technical Skills
Networking
  • Strong understanding of TCP/IP and OSI models.
  • Working knowledge of Routing, Switching, VLANs, DNS, DHCP, NAT, HTTP/HTTPS, and VPN.
  • Ability to perform basic network troubleshooting and understand common network security events.
Operating Systems
  • Strong working knowledge of Windows and Linux operating systems.
  • Understanding of Windows security concepts, services, event logs, processes, and basic troubleshooting.
Endpoint Security

Hands‑on experience with at least one enterprise endpoint security platform such as:

  • Microsoft Defender for Endpoint
  • CrowdStrike
  • SentinelOne
  • Cortex XDR
  • or equivalent EDR/XDR solutions.
Security Technologies

Basic to working knowledge of:

  • NGFW / Firewall
  • WAF
  • Proxy
  • IPS/IDS
  • Email Security
  • SIEM
  • PAM
  • Identity and Access Security
  • Endpoint Detection and Response (EDR/XDR)
Identity Access Security
  • Understanding of Active Directory and Microsoft Entra ID.
  • Knowledge of Group Policy, authentication, authorization, MFA, and account security.
  • Basic understanding of suspicious authentication and unauthorized access scenarios.
Security Monitoring Incident Response
  • Basic hands‑on experience with SIEM platforms and security log analysis.
  • Understanding of common security threats and attack techniques, including:
    • Malware
    • Ransomware
    • Phishing
    • Brute‑force attacks
    • Suspicious authentication
    • Unauthorized access
    • Indicators of Compromise (IOC)
  • Basic understanding of MITRE ATTCK framework and common attack techniques.
  • Ability to perform initial incident triage and determine appropriate escalation paths.
Scripting
  • Basic knowledge of PowerShell or Python is an added advantage.
Preferred Certifications
  • CompTIA Security+
  • Microsoft SC-900 / SC-200
  • CCNA
  • Microsoft Defender / SentinelOne security certifications or fundamentals
  • CEH - preferred but not mandatory
Behavioral Soft Skills
  • Strong analytical, troubleshooting, and problem‑solving skills.
  • Good understanding of security operations and incident management processes.
  • Strong written and verbal communication skills.
  • Ability to work effectively in a 24x7 shift environment.
  • Strong attention to detail and ability to follow defined SOPs and processes.
  • Good documentation and ticket management skills.
  • Ability to work collaboratively with cross‑functional technical teams.
  • Proactive attitude with a strong willingness to learn emerging cybersecurity technologies and threats.
  • Customer‑focused approach with a strong sense of ownership and accountability.
Key Performance Indicators (KPIs)
  • Security acknowledgement and response SLA compliance.
  • Accuracy and effectiveness of incident triage and initial investigation.
  • Quality, completeness, and timeliness of security ticket documentation.
  • Quality and accuracy of shift handovers.
  • Compliance with security tool health‑check and monitoring procedures.
  • Adherence to security SOPs, operational processes, and escalation procedures.
  • Timely and appropriate escalation of security incidents.
  • Contribution to vulnerability remediation and endpoint compliance activities.
  • Continuous technical learning and progress toward relevant cybersecurity certifications.
Experience

4-5 years of relevant experience in:

  • Security Operations / SOC
  • Cybersecurity Operations
  • Security Monitoring
  • Incident Triage and Response
  • Endpoint Security / EDR
  • SIEM Monitoring
  • Enterprise IT Security Operations

Disclaimer: This job description has been sourced from a public domain and may have been modified by Naukri.com to improve clarity for our users. We encourage job seekers to verify all details directly with the employer via their official channels before applying.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Analyst
Security Operations Analyst

ITOrizon • Tiruchirappalli, Bengaluru

On-site
INR 500,000 - 800,000
Structured learning and certification support
Hands-on experience with modern security tools
Clear growth path aligned to performance
Security Operations Center Analyst- L2
Security Operations Center Analyst- L2

Incedo Inc. • Gurugram District

On-site
INR 900,000 - 1,500,000
Security Engineer
Security Engineer

Zensar • Hyderabad

Hybrid
INR 1,400,000 - 2,400,000
SOC L1 Analyst
SOC L1 Analyst

Verint • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Security Analyst - L2
Security Analyst - L2

Nopal Cyber, LLC. • Hyderabad

On-site
INR 1,200,000 - 1,600,000
Security Operations (SecOps) Engineer
Security Operations (SecOps) Engineer

Eclat-Health-Solutions-4 • Hyderabad

On-site
INR 800,000 - 1,500,000
Cybersecurity L1 SOC Analyst
Cybersecurity L1 SOC Analyst

Power Bridge • Bengaluru

On-site
INR 600,000 - 1,200,000
Health insurance
Employer-matched savings plan
Career development opportunities
Security Operations Center Analyst - L2 || Mumbai || Only Immediate Joiner
Security Operations Center Analyst - L2 || Mumbai || Only Immediate Joiner

Innova ESI • Mumbai

On-site
INR 800,000 - 1,200,000
Network Security Operations
Network Security Operations

Cubix Tech • Chennai District

On-site
INR 350,000 - 550,000
Soc Analyst
Soc Analyst

Incedo • Gurugram District

On-site
INR 1,800,000 - 2,400,000
24x7 Rotational Shift
Willingness to work on weekends/holid-