SOC Analyst – L1

Alif Consulting

Pune District

On-site

INR 600,000 - 900,000

Full time

8 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

AlifCloud IT Consulting Pvt. Ltd. is seeking a SOC Analyst – L1 to join our Security Operations Center team in Pune. You will monitor security alerts, conduct initial investigations, and triage incidents using Microsoft Sentinel and KQL in an MSSP environment.

The role requires hands-on experience with Microsoft Sentinel, knowledge of KQL, and a willingness to work in rotational shifts including nights. Prior MSSP exposure and strong incident documentation will be highly valued.

Qualifications

  • Hands-on experience with Microsoft Sentinel mandatory.
  • Good understanding of KQL and ability to write queries for security investigations.
  • Prior MSSP/Managed SOC environment experience required.
  • Experience handling and triaging security alerts/incidents.
  • Basic understanding of Incident Response and SOC processes.
  • Familiarity with SIEM concepts and log analysis.
  • Willingness to work in rotational shifts, including night shifts, weekends and public holidays.

Responsibilities

  • Monitor security alerts and events using Microsoft Sentinel and other security monitoring tools.
  • Perform L1 alert triage and investigate suspicious activities.
  • Analyze logs from endpoints, firewalls, network devices, cloud environments, identity systems, and other security sources.
  • Write and execute KQL queries for alert investigation, threat hunting, and log analysis.
  • Perform initial investigation of security incidents and determine severity, impact, and priority.
  • Identify false positives and perform appropriate alert closure with proper documentation.
  • Escalate confirmed or complex incidents to L2/L3 / Incident Response teams.
  • Have a basic understanding of Incident Response processes, including identification, containment, eradication, and recovery.
  • Follow SOC playbooks, escalation procedures, and incident‑handling processes.
  • Maintain accurate investigation notes and incident documentation.
  • Work with multiple customer environments in an MSSP setup while maintaining SLA requirements.
  • Participate in continuous improvement of detection rules, use cases, and SOC processes.
  • Stay updated on common attack techniques, vulnerabilities, and threat intelligence.

Skills

Microsoft Sentinel
KQL queries
MSSP / Managed SOC experience
SOC operations
Incident Response basics
SIEM concepts
L1 alert triage
Incident documentation
Analytical thinking

Job description

AlifCloud IT Consulting Pvt. Ltd. | Full time

Shift: Rotational Shifts, including Night Shifts

About the Role

We are looking for a SOC Analyst – L1 to join our Security Operations Center team. The ideal candidate should have hands‑on experience working with Microsoft Sentinel, be comfortable writing KQL queries, and have prior experience in an MSSP/SOC environment.

The candidate will be responsible for continuous security monitoring, initial alert investigation, incident triage, escalation, and supporting the incident response team.

Key Responsibilities
  • Monitor security alerts and events using Microsoft Sentinel and other security monitoring tools.
  • Perform L1 alert triage and investigate suspicious activities.
  • Analyze logs from endpoints, firewalls, network devices, cloud environments, identity systems, and other security sources.
  • Write and execute KQL (Kusto Query Language) queries for alert investigation, threat hunting, and log analysis.
  • Perform initial investigation of security incidents and determine severity, impact, and priority.
  • Identify false positives and perform appropriate alert closure with proper documentation.
  • Escalate confirmed or complex incidents to L2/L3 / Incident Response teams.
  • Have a basic understanding of Incident Response (IR) processes, including identification, containment, eradication, and recovery.
  • Follow SOC playbooks, escalation procedures, and incident‑handling processes.
  • Maintain accurate investigation notes and incident documentation.
  • Work with multiple customer environments in an MSSP setup while maintaining SLA requirements.
  • Participate in continuous improvement of detection rules, use cases, and SOC processes.
  • Stay updated on common attack techniques, vulnerabilities, and threat intelligence.
Mandatory Skills & Experience
  • 1–3 years of experience in SOC / Cybersecurity Operations.
  • Hands‑on experience with Microsoft Sentinel is mandatory.
  • Good understanding of KQL and ability to write queries for security investigations.
  • Previous experience working in an MSSP / Managed SOC environment is mandatory.
  • Experience handling and triaging security alerts/incidents.
  • Basic understanding of Incident Response and SOC processes.
  • Basic understanding of SIEM concepts and log analysis.
  • Understanding of common security threats such as phishing, malware, brute‑force attacks, credential attacks, suspicious PowerShell activity, and unauthorized access.
  • Ability to analyze security events and correlate information from multiple log sources.
  • Willingness to work in rotational shifts, including night shifts, weekends, and public holidays.
  • Good communication and incident documentation skills.
Good to Have
  • Experience with Microsoft Defender XDR / Defender for Endpoint / Defender for Identity.
  • Knowledge of Azure and Microsoft Entra ID security.
  • Experience with EDR/XDR platforms.
  • Basic knowledge of network security, firewalls, IDS/IPS, VPN, DNS, and authentication protocols.
  • Knowledge of MITRE ATT&CK framework.
  • Experience creating or tuning Sentinel analytics rules and detection use cases.
  • Relevant certifications such as SC-200, Security+, CEH, or equivalent.
Candidate Profile
  • We are looking for someone who:
  • Can independently perform L1 alert triage.
  • Is comfortable working with Microsoft Sentinel and KQL daily.
  • Understands how an MSSP/SOC operates across multiple customers.
  • Can differentiate between false positives and genuine security incidents.
  • Has a security‑first mindset and strong analytical skills.
  • Is comfortable working under SLA‑driven and shift‑based SOC operations.
  • Is willing to learn and progress toward an L2 SOC / Incident Response role.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst
SOC Analyst

AlifCloud IT Consulting Pvt. Ltd. • Maharashtra

On-site
INR 350,000 - 520,000
Soc Analyst
Soc Analyst

Incedo • Gurugram District

On-site
INR 1,800,000 - 2,400,000
24x7 Rotational Shift
Willingness to work on weekends/holid-
SOC L3 Expert
SOC L3 Expert

Maandag® Middle East • India

On-site
INR 800,000 - 1,200,000
Soc Analyst
Soc Analyst

Genpact • Hyderabad, Bengaluru, New Delhi

Hybrid
INR 900,000 - 1,300,000
Senior Engineering, Security - R01565242
Senior Engineering, Security - R01565242

Brillio • Bengaluru

On-site
INR 400,000 - 640,000
SOC Analyst L1
SOC Analyst L1

Altisec Technologies • Pune District

On-site
INR 800,000 - 1,200,000
Security Analyst - L2
Security Analyst - L2

Nopal Cyber, LLC. • Hyderabad

On-site
INR 1,200,000 - 1,600,000
Security Operations Centre (SOC) Analyst
Security Operations Centre (SOC) Analyst

Owasp10 • Pune District

On-site
INR 420,000 - 600,000
Senior Engineering, Security - R01565242
Senior Engineering, Security - R01565242

Brillio 2 • Bengaluru

On-site
INR 350,000 - 550,000
SOC Analyst – Level 1 (L1)
SOC Analyst – Level 1 (L1)

Techsec Digital Global Private Limited • Mumbai Suburban

On-site
INR 350,000 - 650,000