Senior SOC Analyst

Dynova | vCISO Services

India

On-site

INR 1,200,000 - 1,800,000

Full time

30 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Dynova is seeking an experienced Senior SOC Analyst to join its Cyber Defence function. The role focuses on advanced security monitoring, incident investigation and response, threat hunting, and improving detection across endpoints, cloud, network, and identities.

The successful candidate will own incidents from detection through containment, mentor junior analysts, and contribute to playbooks and on-call SOC operations as needed.

Qualifications

  • 4–7+ years of cybersecurity experience with hands-on SOC/IR.
  • Experience with enterprise SIEM platforms (Elastic Security, Microsoft Sentinel, Splunk or similar).
  • Strong experience with EDR/XDR technologies (Defender, CrowdStrike, Cortex XDR).
  • Understanding of Windows and Linux security.
  • Knowledge of AWS and/or Azure security logs.
  • Experience with IAM and authentication attacks.
  • Ability to write and analyze queries (KQL, ES|QL, EQL, Lucene, SPL).
  • Good understanding of MITRE ATT&CK and attacker TTPs.
  • Strong incident documentation and stakeholder communication.

Responsibilities

  • Monitor security alerts and incidents across SIEM, EDR/XDR, email security, identity, cloud, network, and apps.
  • Perform Tier 2/Tier 3 investigations and escalation for complex incidents.
  • Triage incidents to determine scope, root cause, and remediation actions.
  • Conduct threat hunting using SIEM, EDR/XDR, threat intelligence, and other telemetry.
  • Analyze suspicious activity across endpoints, cloud, and network.
  • Develop and improve SIEM detection rules, queries, dashboards, and alerting logic.
  • Map detection and investigation activities to MITRE ATT&CK.
  • Identify false positives and work with security engineering to improve detection quality.
  • Mentor junior SOC analysts and review escalated investigations.
  • Produce incident reports, SOC metrics, and security trend analysis.
  • Participate in on-call / 24x7 SOC operating model as required.

Skills

SOC/IR experience
SIEM platforms
EDR/XDR
Threat hunting
MITRE ATT&CK
Cloud security
Incident documentation

Tools

Elastic Security
Microsoft Defender
CrowdStrike
Cortex XDR
Splunk
Microsoft Sentinel

Job description

Dynova is an all-in-one cybersecurity service for startups and growing companies across the UAE and GCC, delivered via a virtual CISO on a monthly subscription model. Instead of fragmented security purchases, Dynova provides end-to-end ownership of security outcomes, with vCISOs directing priorities and engineers implementing controls, continuous penetration testing, and 24/7 SOC operations.

Role Overview

We are looking for an experienced Senior SOC Analyst to join our Cyber Defence function. The role will be responsible for advanced security monitoring, incident investigation and response, threat hunting, detection improvement, and supporting junior SOC analysts.

The successful candidate should have strong hands-on experience investigating security incidents across endpoints, identity, cloud, network, and application environments and be comfortable taking ownership of incidents from initial detection through containment and remediation.

Key Responsibilities
  • Monitor, investigate, and respond to security alerts and incidents across SIEM, EDR/XDR, email security, identity, cloud, network, and application platforms.
  • Perform Tier 2/Tier 3 investigation and escalation for complex security incidents.
  • Conduct incident triage, determine scope and impact, identify root cause, and recommend containment and remediation actions.
  • Perform threat hunting using SIEM, EDR/XDR, threat intelligence, and other security telemetry.
  • Analyze suspicious authentication activity, malware, phishing, endpoint events, network activity, cloud events, and potential account compromise.
  • Develop and improve SIEM detection rules, correlation rules, queries, dashboards, and alerting logic.
  • Map detection and investigation activities against the MITRE ATT&CK framework.
  • Identify false positives and work with security engineering teams to improve detection quality.
  • Support incident response activities, evidence collection, investigation timelines, and post-incident reviews.
  • Create and maintain SOC playbooks, SOPs, escalation procedures, and investigation guides.
  • Coordinate with IT, Cloud, DevOps, Application Security, IAM, and other teams during security incidents.
  • Mentor junior SOC analysts and review escalated investigations.
  • Support vulnerability, threat intelligence, and security monitoring activities.
  • Produce incident reports, SOC metrics, management reports, and security trend analysis.
  • Participate in an on-call / 24x7 SOC operating model where required.
Required Experience & Skills
  • 4–7+ years of cybersecurity experience, with significant hands-on SOC/incident response experience.
  • Strong experience with enterprise SIEM platforms, preferably Elastic Security, Microsoft Sentinel, Splunk, or similar.
  • Strong experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, Cortex XDR, or equivalent.
  • Strong understanding of:
  • Windows and Linux security
  • AWS and/or Azure security logs
  • Network security and common protocols
  • Email security and phishing investigations
  • IAM and authentication attacks
  • Experience investigating compromised accounts, malware, suspicious PowerShell, lateral movement, privilege escalation, and cloud security events.
  • Ability to write and analyze queries using KQL, ES|QL, EQL, Lucene, SPL, or similar query languages.
  • Good understanding of MITRE ATT&CK and common attacker TTPs.
  • Strong incident documentation and stakeholder communication skills.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Junior Engineer
Junior Engineer

Lyric Exponentials India Private Limited • Hyderabad

On-site
INR 1,000,000 - 1,500,000
Lead SOC Analyst
Lead SOC Analyst

Sampoorna Consultants • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Technical Specialist - Cyber Security L3
Technical Specialist - Cyber Security L3

Lenovo • Bengaluru

On-site
INR 1,400,000 - 2,100,000
SOC - Senior Associate L2
SOC - Senior Associate L2

Publicis Re:Sources • Gurugram District

On-site
INR 1,200,000 - 2,400,000
Cyber Security Analyst
Cyber Security Analyst

Ace Recruitment Placement Consultants • Pune District

On-site
INR 1,200,000 - 2,400,000
Sr. Security Operations Analyst
Sr. Security Operations Analyst

Simfluent • Dadri

On-site
INR 1,200,000 - 1,800,000
Cyber Security - Subject Matter Expert
Cyber Security - Subject Matter Expert

Lenovo • Bengaluru Urban

On-site
INR 1,500,000 - 2,500,000
SENIOR SUPPORT ENGINEER - Cyber Security
SENIOR SUPPORT ENGINEER - Cyber Security

Happiest Minds Technologies • Dadri

On-site
INR 2,400,000 - 4,200,000
Security Analyst - L2
Security Analyst - L2

Nopal Cyber, LLC. • Hyderabad

On-site
INR 1,200,000 - 1,600,000
Sr. IT Engineer (Security)
Sr. IT Engineer (Security)

DataCore Software • Bengaluru

On-site
INR 4,000,000 - 6,400,000