Soc Analyst

PwC India

Bengaluru

On-site

INR 1,400,000 - 2,200,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

PwC India is seeking a senior SOC professional to lead detection engineering across Splunk and related platforms. You will tune detection logic, map MITRE ATT&CK techniques, and support automation with SCRAT.

You’ll mentor junior Splunk admins and drive improvement through analytics and dashboards. Collaborating with global teams, you will analyze threats, develop complex queries, and help validate detections through red/blue/purple team exercises, ensuring high-fidelity alerts and robust

Qualifications

  • 6-8 years of experience in SOC or security engineering roles.
  • Strong proficiency in analyzing security events across Linux and Windows environments.
  • Expertise with Splunk SPL, KQL and related SIEM query languages.
  • Scripting ability in Python and PowerShell for automation.
  • Experience building detection content and correlation searches.
  • Knowledge of MITRE ATT&CK and mapping to TTPs.
  • Hands-on Splunk ES/UBA/SOAR experience and familiarity with telemetry sources.
  • Certifications in Splunk are a plus.

Responsibilities

  • Develop and fine-tune detection logic and correlation rules in Splunk SIEM and other detection platforms.
  • Collaborate to enhance detection logic and response automation with SCRAT.
  • Participate in daily SOC stand-ups and assist in complex query development.
  • Oversee quality of detection logic, reducing false positives and improving alert fidelity.
  • Ensure telemetry availability with SOC Engineering for effective threat detection.
  • Translate threat intelligence into actionable detection content and coverage.
  • Maintain documentation for detection logic including tuning history.
  • Support threat hunting with custom queries, dashboards, and analytics.
  • Mentor junior Splunk administrators on data ingestion, parsing, indexing, and troubleshooting.
  • Participate in red/blue/purple team exercises to validate detection effectiveness.
  • Contribute to detection-related KPIs and SOC performance reporting.

Skills

Splunk SPL
KQL
Python
PowerShell
SOAR
Threat hunting
MITRE ATT&CK
Detection tuning
Team collaboration

Tools

Splunk ES
UBA
SOAR
Torq

Job description

Key Responsibilities:

  • Operate under the SOC function, reporting to the SOC Manager, with responsibility for developing and fine-tuning detection logic and correlation rules in Splunk SIEM and other detection platforms (e.g., Splunk ES, UBA, SOAR)
  • Collaborate actively with the Global Security Content and Response Automation Team (SCRAT) to enhance detection logic and response automation
  • Participate in daily SOC stand-up calls and provide support for complex query development and troubleshooting
  • Oversee the quality and effectiveness of detection logic, continuously reducing false positives and improving alert fidelity through iterative tuning and feedback
  • Work closely with SOC Engineering to ensure necessary telemetry and event sources are available for effective threat detection
  • Stay up to date with emerging threats and attacker techniques, translating threat intelligence into actionable detection content
  • Maintain comprehensive documentation for detection logic, including rule rationale, expected behaviour, and tuning history.
  • Perform threat coverage gap analysis and mapping using frameworks such as MITRE ATT&CK
  • Support threat hunting initiatives by developing custom queries, dashboards, and analytics
  • Mentor junior Splunk administrators on data ingestion, parsing, indexing, and troubleshooting.
  • Participate in red/blue/purple team exercises to validate and improve detection effectiveness.
  • Assist in the development of detection-related KPIs and metrics for SOC performance reporting.

Skills and Experience:

  • 6-8 years of experience in SOC, threat detection, or security engineering roles
  • Advanced proficiency in analysing security events across both Linux and Windows environments, including log source normalization and enrichment
  • Strong command of SIEM query languages (e.g., Splunk SPL, KQL, CrowdStrike Query Language), with the ability to write complex queries for threat detection, hunting, and anomaly identification
  • Proficiency in scripting languages such as Python and PowerShell, with experience automating detection logic and integrating with orchestration workflows
  • Demonstrated expertise in building and maintaining detection content, including correlation searches and risk-based alerting
  • Deep understanding of the MITRE ATT&CK framework and the ability to accurately map detection logic to specific TTPs
  • Hands-on experience with the Splunk ecosystem, including Enterprise Security (ES), User Behaviour Analytics (UBA), SOAR, and apps like Torq
  • Strong foundational knowledge of cybersecurity principles, threat landscapes, and incident response methodologies
  • Excellent communication and collaboration skills, with the ability to work effectively across SOC, IR, and global engineering teams
  • Strong analytical and problem-solving abilities
  • Splunk certifications (e.g., Admin, Power User, Developer) are a plus
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Consultant
Sr. Consultant

Tribastion Technologies Pvt. Ltd. • India

On-site
INR 1,000,000 - 1,500,000
Soc Engineer
Soc Engineer

HCLTech • Jigani

Hybrid
INR 1,200,000 - 2,400,000
Soc Analyst
Soc Analyst

Bahwan CyberTek • Chennai District, Bengaluru

On-site
INR 600,000 - 900,000
Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

Providence India • Hyderabad

On-site
INR 2,500,000 - 4,500,000
Junior Engineer
Junior Engineer

Lyric Exponentials India Private Limited • Hyderabad

On-site
INR 1,000,000 - 1,500,000
SOC Principal
SOC Principal

HCLSoftware • Bengaluru

On-site
INR 4,500,000 - 7,500,000
SOC L3 Expert
SOC L3 Expert

Maandag® Middle East • India

On-site
INR 800,000 - 1,200,000
Sr SUPPORT ENGINEER - Cyber Security
Sr SUPPORT ENGINEER - Cyber Security

Happiest Minds Technologies • Dadri

On-site
INR 800,000 - 1,500,000
Sr. Security Operations Analyst
Sr. Security Operations Analyst

Simfluent • Dadri

On-site
INR 1,200,000 - 1,800,000
Security Analyst - L2
Security Analyst - L2

Nopal Cyber, LLC. • Hyderabad

On-site
INR 1,200,000 - 1,600,000