SOC Analyst ( Security Analyst – L2)

Soffit Infrastructure Services (P) Ltd

Ernakulam

On-site

INR 600,000 - 900,000

Full time

13 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Soffit Infrastructure Services (P) Ltd is seeking an Information Security Analyst for its SOC. The role focuses on monitoring security events, incident response, and threat remediation in a 24x7 environment, with emphasis on SIEM suites and log analysis.

The candidate will contribute to vulnerability management, dashboards, and security documentation while coordinating with customers as needed.

Qualifications

  • 2-3 years of experience as SOC Analyst.
  • Experience with ELK and Wazuh SIEM preferred.
  • General network knowledge and TCP/IP troubleshooting.
  • Ability to trace down an endpoint on the network from ticket info.
  • Familiarity with system log information and meaning.
  • Understanding of common network services (web, mail, DNS, auth).
  • Knowledge of host-based firewalls, Anti-Malware, HIDS.
  • Knowledge of creating and modifying dashboards.
  • Understanding of firewall, IPS/IDS, NAC functions.
  • Desktop and server OS knowledge; UNIX/Linux & Windows.

Responsibilities

  • Tier 1 SOC analysts are incident responders, remediating attacks escalated from junior analysts.
  • Review vulnerability assessments and focus on deep data dives during/after attacks.
  • Lead efforts to counter SLA breaches and anticipate security alerts.
  • Monitor events from SIEM, Tickets, Email, and Phone; escalate appropriately.
  • Act as team lead for SOC Analysts to safeguard data and platforms.
  • Analyze events, identify root causes, and keep SIEM up to date.
  • Stay updated with emerging threats and regulatory requirements.
  • Document incidents to support IR and DR plans.

Skills

ELK
Wazuh
Splunk
ArcSight
Log analysis
Communication
Incident response
TCP/IP knowledge

Tools

ELK Stack
Wazuh
MimeCast
DMARC Tool

Job description

Job brief

The Security Operation Centre (SOC) Information Security Analyst are the first level responsible for ensuring the protection of digital assets from unauthorized access, identify security incidents and report to customers for both online and on-premises. The position monitors and responds to security events from managed customer security systems as part of a team on a rotating 24 x 7 x 365 basis. They are alert and aggressive to filter out suspicious activity and mitigate risks before any incident occur. Your background should include exposure to security technologies including firewalls, IPS/IDS, logging, monitoring and vulnerability management. You should understand network security practices. Excellent customer service while solving problems should be a top priority for you.

Requirements
Must-haves:
  • 2-3 Year Experience as SOC Analyst - (Experience in SIEM Tool ELK & Wazuh preferable)
  • Process and Procedure adherence
  • General network knowledge and TCP/IP Troubleshooting
  • Ability to trace down an endpoint on the network, based on ticket information
  • Familiarity with system log information and what it means
  • Understanding of common network services (web, mail, DNS, authentication)
  • Knowledge of host-based firewalls, Anti-Malware, HIDS
  • Knowledge of creating and modifying the dashboards.
  • Understanding of common network device functions (firewall, IPS/IDS, NAC)
  • General Desktop OS and Server OS knowledge
  • TCP/IP, Internet Routing, UNIX / LINUX & Windows
  • Deep Knowledge in SIEM, Ticketing tool, EDR, Vulnerability Management, MimeCast, DMARC tool.
  • Excellent written and verbal communication skills.
Good To Have
  • Good to have industry certifications on any SIEM Platform, CEH, C|SA, CompTIA Security+ & Others
Main Responsibilities
  • Tier 1 SOC analysts are incident responders, remediating serious attacks escalated from junior analyst, assessing the scope of the attack, and affected systems, and collecting data for further analysis.
  • Work proactively to seek out weaknesses and stealthy attackers, review vulnerability assessments(CVEs) on monitored assets. Focus more on doing deep dives into datasets to understand what's happening during and after attacks.
  • Leading efforts to counter SLA breaches and anticipating the likelihood of future security alerts,incidents.
  • Monitor security events from the various SOC entry channels (SIEM, Tickets, Email and Phone),based on the security event severity and suspicious activities, elevate to managed service support teams, tier 2 information security specialists, and/or customer as appropriate to perform further investigation and resolution.
  • Works as a Team lead for the SOC Analysts helping them to ensure that corporate data and technology platform components are safeguarded from known threats.
  • Analyse the Events & incidents and identify the root cause.
  • Assist in keeping the SIEM platform up to date and contribute to security strategies as an when newthreats emerge.
  • Staying up to date with emerging security threats including applicable regulatory security requirements.
  • Bring enhancements to SOC security process, procedures, and policies.
  • Document and maintain customer build documents, security procedures and processes.
  • Document incidents to contribute to incident response and disaster recovery plans.
  • Review critical incident reports and scheduled weekly & monthly reports and make sure they are technically and grammatically accurate.
  • Keep updated with new threats, vulnerabilities, create/contribute to use cases, threat hunting etc.
  • Keep updated with the likes of OWASP Top 10 vulnerabilities, Bleeping Computer articles etc., for acquiring the knowledge over current threats in security perspective.
  • Other responsibilities and additional duties as assigned by the security management team or service delivery manager.
Skills
  • Excellent event or log analytical skills
  • Proven experience as IT Security Monitoring or similar role
  • Exceptional organizing and time-management skills
  • Very good communication abilities
  • ELK, Wazuh, Splunk, ArcSight SIEM management skills
  • Reporting
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst ( Security Analyst – L2)
SOC Analyst ( Security Analyst – L2)

Soffit Infrastructure Services (P) Ltd • Ernakulam

On-site
INR 700,000 - 1,000,000
Security Operations Center Analyst
Security Operations Center Analyst

Soffit Infrastructure Services (P) Ltd • Ernakulam

On-site
INR 600,000 - 850,000
Soc Analyst
Soc Analyst

Incedo • Gurugram District

On-site
INR 1,800,000 - 2,400,000
24x7 Rotational Shift
Willingness to work on weekends/holid-
SOC Analyst – L1
SOC Analyst – L1

WORKSENT • Ernakulam

On-site
INR 600,000 - 900,000
Security Analyst - L2
Security Analyst - L2

Nopal Cyber, LLC. • Hyderabad

On-site
INR 1,200,000 - 1,600,000
L2 SOC Analyst
L2 SOC Analyst

UST • Thiruvananthapuram

Hybrid
INR 600,000 - 900,000
Technical Specialist - Cyber Security L3
Technical Specialist - Cyber Security L3

Lenovo • Bengaluru

On-site
INR 1,400,000 - 2,100,000
Security Operations Center Analyst- L2
Security Operations Center Analyst- L2

Incedo Inc. • Gurugram District

On-site
INR 900,000 - 1,500,000
SOC Analyst
SOC Analyst

Access Healthcare • Chennai District

On-site
INR 900,000 - 1,300,000
SOC L1 Analyst
SOC L1 Analyst

Verint • Bengaluru

On-site
INR 1,000,000 - 1,500,000