SOC Analyst L2

Tata Consultancy Services

Chennai District

On-site

INR 2,000,000 - 4,000,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Tata Consultancy Services in Chennai invites a Security Monitoring & Incident Response specialist to lead containment, forensics scoping, and stakeholder updates in line with IR playbooks.

You will work with Defender XDR/MDE, CrowdStrike, and Tanium for rapid endpoint actions; design Cortex XSOAR playbooks and maintain detection content in GitLab; build proactive hunts using MITRE ATT&CK, NIST, and ISO 27001 guidance.

Qualifications

  • Extensive experience in security monitoring and incident response.
  • Hands-on with SIEM, SOAR and EDR platforms in enterprise environments.
  • Strong knowledge of ATT&CK, NIST and ISO 27001 standards and frameworks.

Responsibilities

  • Execute/lead initial containment, forensics scoping, and stakeholder updates; align with IR playbooks.
  • Lead investigations across Defender XDR/MDE and CrowdStrike; assess process trees and signals.
  • Use Tanium for rapid endpoint scoping and live response actions per policy.
  • Analyse Joe Sandbox reports; derive IOCs/YARA candidates; coordinate containment.
  • Design/maintain Cortex XSOAR playbooks; implement data enrichment, containment workflows, and guardrails.

Skills

SIEM
SOAR
EDR
IR frameworks
Threat intel
MITRE ATT&CK
NIST ISO27001
Cloud logs
Threat hunting

Tools

Defender XDR
CrowdStrike
Tanium
Cortex XSOAR
GitLab
Microsoft Sentinel
Elastic
Sigma
Azure AD Entra ID
M365
AWS
GCP
Joe Sandbox

Job description

Role & responsibilities
Security Monitoring & Incident Response
  • Execute/lead initial containment, forensics scoping, and stakeholder updates; align with both best industry practice and internal IR playbooks.
  • Lead investigations across Defender XDR/MDE and CrowdStrike (process trees, lateral movement, identity signals).
  • Use Tanium for rapid endpoint scoping and live response actions (as per policy).
  • Analyse Joe Sandbox reports (behaviour trees, network indicators, dropped files); derive IOCs/YARA candidates; coordinate containment.
  • Design/maintain Cortex XSOAR playbooks (data enrichment, containment workflows, approvals, notifications); implement guardrails.
Threat Detection & Hunting
  • Deep familiarity with Azure AD/Entra ID, Azure Activity/Signin logs, M365 audit logs, as well as AWS and GCP logs.
  • Author and tune analytic rules in Sentinel (KQL), Elastic (DSL/EQL/KQL/ESQL), Sigma; reduce false positives; add entity mapping and suppression logic.
  • Proactive hunts using ATT&CK-aligned hypotheses (credential theft, persistence, C2); pivot across endpoint, identity, network, and cloud logs.
  • Maintain GitLab repos (branching, merge requests, CI checks for detections) and workflows for detection content (code reviews, approvals, CI quality checks).
Expertise:
  • Deep knowledge of SIEM, SOAR, and EDR platforms
  • Deep knowledge of threat intelligence, and incident response frameworks
  • Familiarity with MITRE ATT&CK, NIST, and ISO 27001 standards
  • Ability to analyse logs, network traffic, and malware indicators
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst - L2
Security Analyst - L2

Nopal Cyber, LLC. • Hyderabad

On-site
INR 1,200,000 - 1,600,000
Soc Analyst
Soc Analyst

BUSINESSNEXT • Dadri

On-site
INR 1,200,000 - 2,000,000
Security Analyst
Security Analyst

Access Healthcare • Zone 7 Ambattur

On-site
INR 1,200,000 - 2,100,000
Cyber Security Analyst
Cyber Security Analyst

Ace Recruitment Placement Consultants • Pune District

On-site
INR 1,200,000 - 2,400,000
Soc Analyst 2
Soc Analyst 2

Amerisource Solutions • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Sr. SOC Analyst
Sr. SOC Analyst

Ferfier Technologies • Dadri

Hybrid
INR 1,500,000 - 2,100,000
Flexible/Remote work
Lead SOC Analyst
Lead SOC Analyst

Sampoorna Consultants • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Sr IT Security Analyst SIEM SOAR
Sr IT Security Analyst SIEM SOAR

Technogen • Hyderabad

Hybrid
INR 4,500,000 - 7,500,000
Sr. SOC Engineer (L3)
Sr. SOC Engineer (L3)

Larsen & Toubro • Chennai District

On-site
INR 2,500,000 - 4,000,000
SOC L3 Expert
SOC L3 Expert

Maandag® Middle East • India

On-site
INR 800,000 - 1,200,000