SOC Analyst (Night Shift )

ESP Engineered

Hyderabad

On-site

INR 500,000 - 1,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ESP Engineered is seeking a SOC Analyst for their permanent night shift in Hyderabad. The role involves high-quality alert triage and first-line incident handling with tools like CrowdStrike Falcon and Microsoft Sentinel. Candidates should have 1-5 years in a SOC/security monitoring role, strong alert triage skills, and familiarity with security fundamentals. Participation in a rotation that may include weekends is expected. Opportunities for growth within the SOC will be available.

Qualifications

  • 1–5 years of hands-on SOC experience.
  • Strong focus on alert triage rather than deep forensics.
  • Basic understanding of security fundamentals.

Responsibilities

  • Monitor and triage security alerts from EDR/XDR and SIEM.
  • Conduct basic, playbook-driven mini threat hunting.
  • Analyze and respond to phishing alerts.

Skills

Alert triage
Incident handling
Monitoring
Security fundamentals

Tools

CrowdStrike Falcon
Microsoft Sentinel
Tenable

Job description

We’re looking for a SOC Analyst for our permanent night shift in Hyderabad to focus on high‑quality alert triage and first‑line incident handling. You’ll work mainly with CrowdStrike Falcon, Microsoft Sentinel, and related security tools to keep our global environment safe while most of the company is asleep.

Experience
  • 1–5 years in a SOC / security monitoring role (L1 or L1/L2 mix).
  • Prior experience in a 24/7 or shift‑based SOC is a plus.
  • Permanent night shift, working with EMEA/US time zones.
  • Participation in a rotation that may include weekends and holidays.
  • Clear handover required at the end of each shift to the next region/shift.
  • Monitor and triage security alerts from EDR/XDR (primarily CrowdStrike Falcon), SIEM (Microsoft Sentinel), and other security tools.
  • Quickly review new detections,
  • Decide whether to close as benign/false positive, investigate further, or escalate,
  • Apply standard playbook‑based response actions where allowed (e.g. isolate host, block hash/domain, disable account with approval).
  • Review detections, examine process trees and related activity,
  • Validate severity and impact based on context,
  • Close noise/false positives with clear justification or elevate meaningful events.
  • Use Microsoft Sentinel and other platforms to pull additional context during triage (host history, user activity, geo/access patterns, related alerts).
  • Analyze and respond to phishing alerts and user‑reported suspicious emails using defined playbooks (header analysis, URL/file sandboxing, user follow‑up, ticket updates).
  • Review vulnerability scan results (e.g. Tenable) for basic risk context, confirm exposure where needed, and follow up with the relevant teams according to priority and SLAs.
  • Conduct basic, playbook‑driven “mini threat hunting” during quieter periods (e.g. running saved queries/hunts in Sentinel and EDR to look for common attacker techniques or newly published IOCs).
  • Keep tickets, incident records, and runbooks up to date with short, precise, and complete investigation notes (what triggered, what you checked, what you decided, and why).
  • Produce clear shift‑end handover notes for open incidents and important observations.
What we’re looking for
Core SOC / triage skills
  • 1–5 years of hands‑on SOC experience in monitoring, triage, and first‑line incident handling (L1 or L1/L2).
  • Strong focus on alert triage rather than deep forensics: able to work through a queue efficiently, recognize patterns, and make clear decisions (close, investigate further, elevate).
  • Experience with:
  • At least one enterprise EDR/XDR platform (ideally CrowdStrike Falcon) for alert analysis and basic response (host isolation, hash/domain blocking, evidence collection).
  • A SIEM platform (ideally Microsoft Sentinel) for correlating alerts and running queries to gather additional context.
  • Good understanding of security fundamentals:
  • Logs: endpoint, authentication, OS, and basic application logs.
  • Endpoints: Windows and/or Linux basics, common processes and admin tools.
  • Networks: TCP/IP basics, DNS, web traffic, VPN and remote access patterns.
  • Common attack techniques across the kill chain (phishing, credential theft, lateral movement, malware execution, C2, data exfiltration).
Tools and platforms
  • Familiarity with some of the following (or similar solutions):
  • CrowdStrike Falcon or another modern EDR/XDR platform.
  • Microsoft Sentinel or another SIEM (including experience running and understanding queries; KQL is a plus).
  • Vulnerability management tools such as Tenable.
  • Email security / anti‑phishing tools, sandboxing, or secure email gateways.
Ways of working and soft skills
  • Comfortable working permanently in night shift and collaborating with global teams spread across regions.
  • Strong written communication: able to document alerts, investigations, and handovers in clear, concise English.
  • Ability to stay calm, structured, and pragmatic during active incidents and high‑alert periods.
  • Habit of following runbooks and escalation paths, while also giving feedback when you see gaps or improvement opportunities.
  • Ownership mindset: you close the loop on alerts you touch, or you hand them over with enough context that the next person can continue smoothly.
Nice to have
  • Experience in a 24/7 SOC environment with strict SLAs.
  • Hands‑on experience specifically with CrowdStrike Falcon and Microsoft Sentinel in a production environment.
  • Exposure to SOAR / automation and working with automated playbooks for common use cases (phishing, malware, brute force, etc.).
  • Familiarity with basic vulnerability prioritization (CVSS concepts, asset criticality).
  • Security certifications such as:
  • CompTIA Security+, CySA+,
  • CEH,
Growth and development

Even though this role is centered on triage, we want people who are interested in growing further within the SOC. Over time, you’ll have opportunities to:

  • Take on more complex investigations and incident response tasks under guidance from senior analysts.
  • Get involved in improving detection rules, tuning alerts, and enhancing runbooks.
  • Develop towards specialist tracks such as incident response, threat hunting, or detection engineering depending on your strengths and interests.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst – Level 1
SOC Analyst – Level 1

Soffit Infrastructure Services (P) Ltd • Gurugram District

On-site
INR 600,000 - 900,000
SOC Analyst
SOC Analyst

Kratikal Tech Private Limited • Dadri

On-site
INR 400,000 - 600,000
Health insurance
Gratuity payment
Employees' Provident Fund
L2 SOC Analyst
L2 SOC Analyst

UST • Thiruvananthapuram

Hybrid
INR 600,000 - 900,000
Junior Engineer
Junior Engineer

Lyric Exponentials India Private Limited • Hyderabad

Hybrid
INR 1,000,000 - 1,500,000
SOC Manager
SOC Manager

Sisainfosec • Bengaluru

On-site
INR 1,500,000 - 2,500,000
SOC L3 Expert
SOC L3 Expert

Maandag® Middle East • India

On-site
INR 800,000 - 1,200,000
Senior Security Analyst - SOC
Senior Security Analyst - SOC

Mobileum • Gurugram District

On-site
INR 2,500,000 - 4,000,000
Information Security Specialist
Information Security Specialist

ZEISS India • Bengaluru

On-site
INR 800,000 - 1,200,000
Soc Analyst
Soc Analyst

Incedo • Gurugram District

On-site
INR 1,800,000 - 2,400,000
24x7 Rotational Shift
Willingness to work on weekends/holid-
SOC Manager
SOC Manager

SISA • Bengaluru

On-site
INR 6,000,000 - 9,000,000