Company: Provision Technologies LLP
Location: Gangtok, Sikkim
Employment type: Full-time | On-site
Experience: 2+ years
Work mode: 24×7 rotational shifts
About the role:
Provision Technologies LLP is looking for a SOC Analyst – L1 to join our Security Operations team supporting a critical infrastructure environment in Gangtok, Sikkim.
The L1 Analyst will be the first line of defence, responsible for monitoring security events, performing initial alert triage, identifying potential threats and escalating genuine incidents to the L2/Security Engineering team.
Key responsibilities:
- Monitor security alerts and events through SIEM and SOC platforms
- Perform first-level alert triage, validation and classification
- Analyse logs from firewalls, servers, endpoints, network devices and authentication systems
- Identify suspicious activities, Indicators of Compromise (IOCs) and potential security incidents
- Perform basic investigation and event correlation
- Escalate confirmed or high-risk incidents to L2
- Monitor security events across IT infrastructure and, where applicable, OT/SCADA environments
- Perform basic threat intelligence enrichment of IPs, domains, URLs and file hashes
- Create and maintain incident tickets with accurate investigation details
- Maintain shift handover notes, incident records and daily SOC reports
- Monitor the health of log sources and escalation ingestion/connectivity issues
- Follow established SOC SOPs, incident response procedures and escalation matrices
- Work closely with L2 analysts, security engineers and the customer IT/OT team
Required skills:
- Good understanding of SOC operations and SIEM
- Practical experience in security alert monitoring and log analysis
- Understanding of:
- TCP/IP, DNS, HTTP/HTTPS, SMTP, SSH and VPN
- Firewalls and network security
- Windows and Linux fundamentals
- Endpoint security / EDR
- Understanding of common cyber threats such as:
- Phishing
- Malware
- Brute-force attacks
- Credential compromise
- Privilege escalation
- Lateral movement
- Command & Control
- Data exfiltration
- Good analytical and problem-solving skills
- Strong written and verbal communication
- Good incident documentation and reporting skills
Qualification & experience:
- B.Tech/B.E./BCA/B.Sc./MCA/M.Sc. in Computer Science, IT, Cybersecurity or equivalent
- Minimum 2 years of relevant IT/Security experience
- Preferably 1.5–2+ years of hands-on SOC/Security Monitoring experience
- Experience with any SIEM platform is preferred
- Certifications such as Security+, CEH, CySA+, CSA or SC-200 will be an advantage
Important:
- This is an on-site position in Gangtok, Sikkim
- Candidates must be willing to relocate to Gangtok
- Willingness to work in 24×7 rotational shifts is essential
- Candidates with only theoretical knowledge or certification-based exposure, without practical SOC experience, may not be suitable