SOAR Engineer

Persistent Systems

Pune District

On-site

INR 1,500,000 - 2,200,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Persistent Systems is seeking a SOC L3 Analyst to lead investigations, design detection content in Splunk, and drive incident response improvements. You will work with EDR tools like CrowdStrike, and develop automated SOAR workflows to streamline containment and remediation across a 24/7 operations team.

The role emphasizes threat hunting, security content engineering, and collaboration with threat intelligence and IT teams to enhance the organization’s security posture.

Qualifications

  • Bachelor's degree in computer science, information security, or related field.
  • 8–11 years of cybersecurity experience focusing on SOC operations and incident response.
  • Proficiency with Splunk advanced search, dashboards, and content engineering.
  • Strong expertise in EDR tools such as CrowdStrike.
  • Experience with SOAR platforms and automated workflows.
  • Excellent analytical and communication skills.
  • Willingness to work in 24/7 shifts.

Responsibilities

  • Lead investigations and responses to high-severity security incidents.
  • Develop remediation plans to contain threats.
  • Design and develop detection rules, alerts, and dashboards in Splunk.
  • Improve detection content based on emerging threats.
  • Monitor, analyze, and respond to endpoint threats with EDR tools.
  • Develop automated SOAR workflows and playbooks.
  • Conduct threat hunting and develop use cases.
  • Mentor L1/L2 analysts and share best practices.
  • Document incident response activities and prepare reports.

Skills

Incident response
Threat hunting
Security engineering
Dashboarding
Analytical skills
Communication
Mentoring

Education

Bachelors in CS/InfoSec
CISSP
GCIH
GCFA
Splunk certifications
CSA

Tools

Splunk
CrowdStrike
SOAR
EDR tools
Playbooks

Job description

As a SOC L3 Analyst, you will be responsible for leading the investigation and response to complex security incidents, engineering advanced detection content, and optimizing security tools and processes. With a strong focus on Splunk, content engineering, Endpoint Detection and Response (EDR), and Security Orchestration, Automation, and Response (SOAR), you will enhance the SOCs capabilities to detect and mitigate advanced cyber threats.

  • Location: Pune
  • Experience: Between 8 to 12 Years
  • Job Type: Full Time Employment
What You'll Do:
  • Advanced Incident Response: - Lead the investigation and response to high-severity security incidents, performing deep-dive analysis and root cause determination.
  • Develop and execute remediation plans to contain and eradicate threats.
  • Content Engineering: - Design and develop advanced detection rules, alerts, and dashboards in Splunk to enhance threat detection capabilities.
  • Continuously improve detection content based on emerging threats and attack patterns.
  • Endpoint Detection and Response (EDR): - Utilize EDR tools (e.g., CrowdStrike, Carbon Black) to monitor, analyze, and respond to endpoint threats.
  • Conduct advanced forensic analysis on compromised systems to identify indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) used by threat actors.
  • Security Orchestration, Automation, and Response (SOAR): - Develop and maintain automated workflows and playbooks on the SOAR platform to streamline incident response processes.
  • Integrate SOAR with other security tools and systems to automate threat detection, investigation, and response tasks.
  • Threat Hunting: - Conduct proactive threat hunting activities to identify hidden threats and security weaknesses within the environment.
  • Develop and implement threat hunting methodologies and use cases.
  • Collaboration and Mentoring: - Collaborate with other SOC analysts, threat intelligence teams, and IT departments to improve overall security posture.
  • Provide mentorship and guidance to L1 and L2 analysts, sharing knowledge and best practices.
  • Security Tool Optimization: - Optimize the configuration and performance of security tools, including Splunk, EDR, and SOAR platforms.
  • Evaluate and recommend new security technologies and solutions to enhance SOC capabilities.
  • Documentation and Reporting: - Document incident response activities, findings, and outcomes in detail.
  • Prepare comprehensive reports and briefings for senior management and stakeholders on security incidents and SOC performance.
  • Continuous Improvement: - Stay updated with the latest cybersecurity threats, trends, and technologies.
  • Participate in training and professional development activities to enhance skills and knowledge.
Expertise You'll Bring:
  • Bachelors degree in computer science, Information Security, or a related field, or equivalent experience.
  • 8 to 11 years of experience in cybersecurity, with a focus on SOC operations, incident response, and security engineering.
  • Proficiency with Splunk, including advanced search, dashboard creation, and content engineering.
  • Strong expertise in EDR tools such as CrowdStrike, or similar.
  • Experience with SOAR platforms and developing automated workflows and playbooks.
  • Excellent analytical, problem-solving, and communication skills.
  • Ability to work independently and as part of a team in a fast-paced environment.
  • Certified Information Systems Security Professional (CISSP)- GIAC Certified Incident Handler (GCIH)- GIAC Certified Forensic Analyst (GCFA)- Splunk Certified User/Power User/Architect- Certified SOAR Analyst (CSA)
  • Working Conditions: - This role requires working in shifts to provide 24/7 security monitoring.
  • Competitive salary and benefits package
  • Culture focused on talent development with quarterly growth opportunities and company-sponsored higher education and certifications
  • Opportunity to work with cutting-edge technologies
  • Employee engagement initiatives such as project parties, flexible work hours, and Long Service awards
  • Insurance coverage: group term life, personal accident, and Mediclaim hospitalization for self, spouse, two children, and parents
Values-Driven, People-Centric & Inclusive Work Environment:

Persistent is dedicated to fostering diversity and inclusion in the workplace. We invite applications from all qualified individuals, including those with disabilities, and regardless of gender or gender preference. We welcome diverse candidates from all backgrounds.

  • We support hybrid work and flexible hours to fit diverse lifestyles.
  • Our office is accessibility-friendly, with ergonomic setups and assistive technologies to support employees with physical disabilities.
  • If you are a person with disabilities and have specific requirements, please inform us during the application process or at any time during your employment.
Let's unleash your full potential at Persistent - persistent.com/careers

Persistent is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst
Security Analyst

Persistent Systems • Bengaluru

Hybrid
INR 1,500,000 - 2,300,000
Hybrid work
Flexible work hours
Long Service awards
+3
Cyber Security Engineer
Cyber Security Engineer

Persistent Systems Limited • Pune District

On-site
INR 1,500,000 - 2,200,000
Hybrid work model
Insurance coverage
Talented development opportunities
+1
SOAR Architect
SOAR Architect

Persistent Systems • Pune City

Hybrid
INR 1,200,000 - 1,800,000
Competitive salary and benefits package
Quarterly promotion cycles
Insurance coverage for family
+2
Sr. Cyber Security Analyst
Sr. Cyber Security Analyst

Rectitude Consulting Services • Maharashtra

Hybrid
INR 1,800,000 - 2,400,000
Competitive salary
Performance-based incentives
Professional growth opportunities
Security Operations Engineer
Security Operations Engineer

NextGenEnergyJobs • Bengaluru

On-site
INR 2,500,000 - 5,200,000
Flexible time off
Wellness resources
Team events
L3 SOC Security Analyst/Bangalore,Noida,Chennai
L3 SOC Security Analyst/Bangalore,Noida,Chennai

Hirexa Solutions • Chennai District, Bengaluru, Dadri

Hybrid
INR 2,800,000 - 4,200,000
Security Architect
Security Architect

Accenture • Mumbai

On-site
INR 3,500,000 - 5,500,000
IN_Senior Associate_SOC_Cyber Defense And Engineering_ Advisory _Mumbai
IN_Senior Associate_SOC_Cyber Defense And Engineering_ Advisory _Mumbai

PwC • Navi Mumbai

On-site
INR 1,500,000 - 2,500,000
SOC Specialist
SOC Specialist

METRO/MAKRO • Pune District

On-site
INR 4,000,000 - 7,000,000
Vapt Engineer
Vapt Engineer

Persistent Systems • Pune District

Hybrid
INR 1,200,000 - 2,200,000
Hybrid work arrangement
Long Service awards
Group term life insurance
+1