Walk-in | Senior Security Analyst

Access Healthcare

Chennai District

On-site

INR 900,000 - 1,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Access Healthcare is looking for an experienced Security Analyst (Tier 2) to join their Security Operations Center (SOC) team in Chennai. The role involves managing SIEM platforms, leading incident response activities, and developing detection rules.

Candidates should have a background in Cyber Security, with minimum 5 years of SOC experience and relevant certifications. The position requires strong technical skills to monitor cyber threats and enhance incident response.

Qualifications

  • Minimum 5 years in a SOC / Security Operations environment.
  • Hands-on experience with SIEM tools.
  • Relevant certifications like CEH, GCIH or equivalent.

Responsibilities

  • Manage and maintain the SIEM platform.
  • Lead Tier 2 incident response activities.
  • Document investigation steps and findings.
  • Perform root cause analysis on significant incidents.
  • Develop and maintain detection rules and dashboards.
  • Automate repetitive triage tasks through SOAR playbooks.

Skills

SIEM platform management
Tier 2 incident response
Root cause analysis (RCA)
Detection rules development
Threat intelligence operationalization
Cybersecurity incident investigation
EDR platforms experience

Education

Degree in Information Technology/Cyber Security

Tools

SIEM tools (Splunk, Microsoft Sentinel, QRadar)
EDR tools (CrowdStrike Falcon, Microsoft Defender, SentinelOne)
ITSM tools (ServiceNow, Jira)

Job description

Department: Information Security / Security Operations Center (SOC)

Designation: L2 Information Security

Reporting To: SOC Manager

Experience: Minimum 5 years in a SOC / Security Operations environment

Work Pattern: Rotating shift model (24x7)

Work Location: Ambattur, Chennai

Role

We are seeking an experienced Security Analyst (Tier 2) to join our Security Operations Center (SOC) team. The successful candidate will serve as a subject matter expert in enterprise security monitoring, responsible for the detection, investigation, and response to cybersecurity incidents and threats across a large-scale, complex enterprise environment.

Responsibilities
  • Manage and maintain the SIEM platform ensuring log ingestion health, data source onboarding, parser validation, and rule accuracy.
  • Lead and coordinate Tier 2 incident response activities containing, eradicating, and recovering from security incidents in line with the SOC IR playbook and defined SLAs.
  • Document all investigation steps, findings, evidence, and actions taken accurately within the ITSM / ticketing system (e.g. ServiceNow, Jira).
  • Perform root cause analysis (RCA) on significant incidents and contribute lessons learned to post-incident review reports.
  • Develop, tune, and maintain detection rules, correlation rules, and dashboards to improve coverage across the MITRE ATT&CK framework.
  • Identify log source gaps and work with IT and infrastructure teams to onboard missing data sources into the SIEM.
  • Automate repetitive triage tasks through SOAR playbooks (e.g. Cortex XSOAR, Sentinel Logic Apps) to improve analyst efficiency and reduce MTTD/MTTR.
  • Monitor and investigate endpoint telemetry using EDR platforms (e.g. CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne) to detect malicious activity including malware, ransomware, and living off-the-land (LotL) attacks.
  • Analyse firewall logs and network traffic data (Palo Alto, FortiGate, Cisco ASA, Check Point) to identify suspicious traffic patterns, policy violations, and network-based threats.
  • Investigate alerts originating from IDS/IPS systems, web proxies, DNS security platforms, and network detection and response (NDR) solutions.
  • Consume and operationalize threat intelligence feeds (commercial and open-source) triaging IOCs, enriching alerts, and updating blocking lists in SIEM, firewall, and EDR platforms.
  • Track active threat campaigns, adversary groups, and CVEs relevant to the organization’s sector and technology stack.
  • Collaborate with IT, infrastructure, and engineering teams on threat remediation
Qualification
  • Any degree in information technology specialization in Cyber Security/ Forensic, computer science, Information Technology
  • 5 to 7 years of experience working in a 24x7 Security Operation Center (SOC) environment.
  • Hands‑on experience working with any of the SIEM tools (Splunk, Microsoft Sentinel, or QRadar)
  • EDR expertise (CrowdStrike Falcon, Microsoft Defender, SentinelOne, or Cortex XDR)
  • Relevant certifications such as CEH, CHFI, COMPTIA +, GCIA, GCIH, Splunk, Elastic, Microsoft Sentinel, QRadar, or equivalent.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst
SOC Analyst

Access Healthcare • Chennai District

On-site
INR 900,000 - 1,300,000
Security Operations Center Analyst - L2 || Mumbai || Only Immediate Joiner
Security Operations Center Analyst - L2 || Mumbai || Only Immediate Joiner

Innova ESI • Mumbai

On-site
INR 800,000 - 1,200,000
Soc Analyst
Soc Analyst

Incedo • Gurugram District

On-site
INR 1,800,000 - 2,400,000
24x7 Rotational Shift
Willingness to work on weekends/holid-
Cyber Analyst.
Cyber Analyst.

Cortex Consultants LLC • Chennai

On-site
INR 1,500,000 - 2,500,000
L2 SOC Analyst
L2 SOC Analyst

UST • Thiruvananthapuram

Hybrid
INR 600,000 - 900,000
CYBER security Analyst
CYBER security Analyst

Cortex Consultants LLC • Chennai

On-site
INR 1,200,000 - 1,800,000
Engineer II - L2 SOC
Engineer II - L2 SOC

Wipfli • Bengaluru

On-site
INR 1,200,000 - 1,800,000
SOC L1 Analyst
SOC L1 Analyst

Verint • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Security Analyst - L2
Security Analyst - L2

Nopal Cyber, LLC. • Hyderabad

On-site
INR 1,200,000 - 1,600,000
SOC Analyst (L1)
SOC Analyst (L1)

Wishtree Technologies • Ahmedabad District

On-site
INR 600,000 - 900,000