SOC Analyst

AlifCloud IT Consulting Pvt. Ltd.

Maharashtra

On-site

INR 350,000 - 520,000

Full time

8 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

AlifCloud IT Consulting Pvt. Ltd. is seeking a SOC Analyst – L1 for its Security Operations Center in India. You will monitor alerts, perform initial triage, and support incident response across multiple customers in an MSSP setup.

The role requires hands-on Microsoft Sentinel experience, proficient KQL skills, and the ability to work rotational shifts including nights. Strong documentation and collaboration with incident response teams are essential.

Qualifications

  • 1–3 years of experience in SOC / Cybersecurity Operations.
  • Hands-on experience with Microsoft Sentinel is mandatory.
  • Good understanding of KQL and ability to write queries for security investigations.
  • Previous MSSP / Managed SOC experience is mandatory.
  • Experience handling and triaging security alerts/incidents.
  • Basic understanding of Incident Response and SOC processes.
  • Basic understanding of SIEM concepts and log analysis.
  • Understanding of common security threats such as phishing, malware, brute‑force attacks, credential attacks, suspicious PowerShell activity, and unauthorized access.
  • Willingness to work in rotational shifts, including night shifts, weekends, and public holidays.
  • Good communication and incident documentation skills.

Responsibilities

  • Monitor security alerts and events using Microsoft Sentinel and other security monitoring tools.
  • Perform L1 alert triage and investigate suspicious activities.
  • Analyze logs from endpoints, firewalls, network devices, cloud environments, identity systems, and other security sources.
  • Write and execute KQL (Kusto Query Language) queries for alert investigation, threat hunting, and log analysis.
  • Perform initial investigation of security incidents and determine severity, impact, and priority.
  • Identify false positives and perform appropriate alert closure with proper documentation.
  • Escalate confirmed or complex incidents to L2/L3 / Incident Response teams.
  • Have a basic understanding of Incident Response (IR) processes, including identification, containment, eradication, and recovery.
  • Follow SOC playbooks, escalation procedures, and incident‑handling processes.
  • Maintain accurate investigation notes and incident documentation.
  • Work with multiple customer environments in an MSSP setup while maintaining SLA requirements.
  • Participate in continuous improvement of detection rules, use cases, and SOC processes.
  • Stay updated on common attack techniques, vulnerabilities, and threat intelligence.

Skills

KQL queries
Incident triage
SOC operations
Security monitoring
Log analysis

Tools

Microsoft Sentinel

Job description

Shift: Rotational Shifts, including Night Shifts

About the Role

We are looking for a SOC Analyst – L1 to join our Security Operations Center team. The ideal candidate should have hands‑on experience working with Microsoft Sentinel, be comfortable writing KQL queries, and have prior experience in an MSSP/SOC environment.

The candidate will be responsible for continuous security monitoring, initial alert investigation, incident triage, escalation, and supporting the incident response team.

Key Responsibilities
  • Monitor security alerts and events using Microsoft Sentinel and other security monitoring tools.
  • Perform L1 alert triage and investigate suspicious activities.
  • Analyze logs from endpoints, firewalls, network devices, cloud environments, identity systems, and other security sources.
  • Write and execute KQL (Kusto Query Language) queries for alert investigation, threat hunting, and log analysis.
  • Perform initial investigation of security incidents and determine severity, impact, and priority.
  • Identify false positives and perform appropriate alert closure with proper documentation.
  • Escalate confirmed or complex incidents to L2/L3 / Incident Response teams.
  • Have a basic understanding of Incident Response (IR) processes, including identification, containment, eradication, and recovery.
  • Follow SOC playbooks, escalation procedures, and incident‑handling processes.
  • Maintain accurate investigation notes and incident documentation.
  • Work with multiple customer environments in an MSSP setup while maintaining SLA requirements.
  • Participate in continuous improvement of detection rules, use cases, and SOC processes.
  • Stay updated on common attack techniques, vulnerabilities, and threat intelligence.
Mandatory Skills & Experience
  • 1–3 years of experience in SOC / Cybersecurity Operations.
  • Hands‑on experience with Microsoft Sentinel is mandatory.
  • Good understanding of KQL and ability to write queries for security investigations.
  • Previous experience working in an MSSP / Managed SOC environment is mandatory.
  • Experience handling and triaging security alerts/incidents.
  • Basic understanding of Incident Response and SOC processes.
  • Basic understanding of SIEM concepts and log analysis.
  • Understanding of common security threats such as phishing, malware, brute‑force attacks, credential attacks, suspicious PowerShell activity, and unauthorized access.
  • Ability to analyze security events and correlate information from multiple log sources.
  • Willingness to work in rotational shifts, including night shifts, weekends, and public holidays.
  • Good communication and incident documentation skills.
Good to Have
  • Experience with Microsoft Defender XDR / Defender for Endpoint / Defender for Identity.
  • Knowledge of Azure and Microsoft Entra ID security.
  • Experience with EDR/XDR platforms.
  • Basic knowledge of network security, firewalls, IDS/IPS, VPN, DNS, and authentication protocols.
  • Knowledge of MITRE ATT&CK framework.
  • Experience creating or tuning Sentinel analytics rules and detection use cases.
  • Relevant certifications such as SC-200, Security+, CEH, or equivalent.
Candidate Profile

We are looking for someone who:

  • Can independently perform L1 alert triage.
  • Is comfortable working with Microsoft Sentinel and KQL daily.
  • Understands how an MSSP/SOC operates across multiple customers.
  • Can differentiate between false positives and genuine security incidents.
  • Has a security-first mindset and strong analytical skills.
  • Is comfortable working under SLA‑driven and shift‑based SOC operations.
  • Is willing to learn and progress toward an L2 SOC / Incident Response role.

Candidates without hands‑on Microsoft Sentinel and KQL experience, or without prior MSSP/SOC experience, may not be considered.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst – L1
SOC Analyst – L1

Alif Consulting • Pune District

On-site
INR 600,000 - 900,000
Security Operations Center Analyst- L2
Security Operations Center Analyst- L2

Incedo Inc. • Gurugram District

On-site
INR 900,000 - 1,500,000
Soc Analyst
Soc Analyst

Incedo • Gurugram District

On-site
INR 1,800,000 - 2,400,000
24x7 Rotational Shift
Willingness to work on weekends/holid-
SOC L3 Expert
SOC L3 Expert

Maandag® Middle East • India

On-site
INR 800,000 - 1,200,000
Senior SOC (Security Operations Center) Analyst
Senior SOC (Security Operations Center) Analyst

Orcapod Consulting Services • Mumbai

Hybrid
INR 1,200,000 - 1,800,000
Senior Engineering, Security - R01565242
Senior Engineering, Security - R01565242

Brillio 2 • Bengaluru

On-site
INR 350,000 - 550,000
Senior Engineering, Security - R01565242
Senior Engineering, Security - R01565242

Brillio • Bengaluru

On-site
INR 400,000 - 640,000
Lead SOC Analyst
Lead SOC Analyst

Sampoorna Consultants • Bengaluru

On-site
INR 1,000,000 - 1,500,000
SOC L1 Analyst
SOC L1 Analyst

Verint • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Security Analyst - L2
Security Analyst - L2

Nopal Cyber, LLC. • Hyderabad

On-site
INR 1,200,000 - 1,600,000