Soc Engineer

VPS Lakeshore

Ernakulam

On-site

INR 1,200,000 - 2,500,000

Full time

7 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

VPS Lakeshore Medical Centre is seeking a SOC Engineer to own day-to-day security monitoring and incident response across hospital systems including HIS/EMR, PACS, LIS, and connected devices. You will implement and run SIEM, EDR/XDR, and SOAR tooling, investigate threats, and drive incidents to closure with IT Operations and application teams.

The role demands hands-on technical depth, strong documentation, and an evidence-led approach to protect patient data and ensure 24x7 availability.

Qualifications

  • Bachelor's degree in Computer Science, IT, Cyber Security or related field.
  • 6+ years of hands-on information security experience with at least 2 years in SOC.
  • Experience administering and tuning SIEM platforms with onboarding sources, rules, and dashboards.
  • Experience investigating and closing security incidents end-to-end with documentation.

Responsibilities

  • Implement, configure, and optimise SOC tooling (SIEM, EDR/XDR, SOAR).
  • Manage log collection from devices, servers, applications, and cloud into the SIEM.
  • Monitor logs and events to identify threats and triage alerts by severity.
  • Develop SIEM use cases, correlations, and dashboards to reduce false positives.
  • Conduct incident investigations, determine root cause, and coordinate remediation.
  • Create and maintain incident tickets with proper documentation and SLAs.
  • Consume threat intelligence for healthcare and perform proactive hunting.
  • Support vulnerability scanning, patch reporting, and remediation tracking.
  • Monitor phishing, malware, anomalous logins, and identity security controls.
  • Collaborate with clinical, biomedical, and IT teams to monitor clinical devices.
  • Coordinate with IT Ops and vendors for containment and resolution.
  • Maintain SOC playbooks, SOPs, and reporting metrics.

Skills

SIEM administration
EDR/XDR
SOAR platforms
Log management
Incident response
Threat hunting
Networking basics
Windows admin
Linux admin
Active Directory / Entra ID

Education

Bachelor's degree in Computer Science or related field

Tools

Microsoft Sentinel
Splunk
IBM QRadar

Job description

SOC Engineer

Security Operations Centre Monitoring, Detection & Incident Response

POSITION PURPOSE

The SOC Engineer owns the day-to-day security monitoring and incident response capability of VPS Lakeshore Medical Centre. A hospital runs 24x7 on systems that hold patient data including HIS/EMR, PACS, LIS, pharmacy, billing, Active Directory, and a large estate of connected clinical devices. A security incident in this environment is a patient-safety and continuity-of-care issue and is of a critical nature. The role is responsible for implementing and running the hospital's security tooling (SIEM, EDR/XDR, SOAR), detecting and investigating threats across that estate, driving incidents to closure with the IT Operations and application teams, and continuously improving detection quality so that real threats surface early and noise does not. The SOC Engineer must combine strong hands-on technical depth with disciplined documentation and an evidence-led approach under pressure.

KEY RESPONSIBILITIES
  • SOC Tool Implementation & Administration — Implement, configure, maintain, and optimise SOC tooling. This includes but is not limited to SIEM, EDR/XDR, SOAR, and other security monitoring solutions as decided upon with management.
  • Log Management & Integration — Manage log collection and onboarding from network devices, firewalls, servers, endpoints, security devices, clinical and business applications, and cloud platforms into the SIEM; validate parsing, normalisation, time synchronisation, and log-source availability, and act on ingestion failures.
  • Security Monitoring & Log Analysis — Monitor and analyse security logs, events, and alerts to identify suspicious activity, anomalies, threats, and potential security incidents; triage alerts by severity and business impact, and maintain a clean, documented handover at the end of each shift or on-call window.
  • Use Case Engineering & Rule Tuning — Develop, maintain, and tune SIEM correlation rules, alerts, dashboards, and security use cases mapped to attacks; measure and reduce false positives; build detections for hospital-specific risks such as unauthorised access to patient records, privileged account misuse, and ransomware precursor behaviour.
  • Incident Investigation & Response — Perform incident investigation, establish root cause and scope, preserve evidence, and coordinate with the relevant teams for containment, eradication, remediation, recovery, and closure; follow defined incident response playbooks and support post-incident reviews.
  • Incident Ticket Management — Create, update, track, and close security incident tickets with proper documentation, evidence, categorisation, prioritisation, escalation, and resolution notes, in line with agreed SLAs.
  • Threat Intelligence & Threat Hunting — Consume threat intelligence feeds and advisories relevant to healthcare; perform IOC analysis and proactive threat hunting across endpoint, network, identity, and cloud telemetry to find activity that existing detections have missed.
  • Vulnerability & Exposure Support — Work with external agencies to support vulnerability scanning, patch-compliance reporting, and remediation follow-up with IT Operations and application owners; track closure of critical and high findings on the hospital estate.
  • Email, Endpoint & Identity Security — Monitor and respond to phishing reports, malware detections, account compromise, and anomalous authentication activity; support email security, endpoint protection, MFA, conditional access, and privileged access controls.
  • Clinical & Biomedical Environment Security — Work with the biomedical, applications, and infrastructure teams to bring clinical systems and connected medical devices (IoMT) into monitoring scope, respecting clinical availability and vendor-support constraints.
  • IT Infrastructure Coordination — Coordinate with IT Operations, network, server, application, and vendor teams for security incident investigation, containment, and resolution, and for changes that affect the security monitoring estate.
  • Documentation, Playbooks & SOPs — Maintain SOC documentation like response playbooks, escalation matrices, log-source inventory, and use‑case catalogue.
  • Reporting & Metrics — Produce periodic security reports and metrics like alert and incident volumes, detection coverage, mean time to detect and respond, false-positive rate, open risks for the Head of IT and hospital management.
QUALIFICATIONS & EXPERIENCE
  • Bachelor's degree in Computer Science, Information Technology, Cyber Security, Electronics, or a related field.
  • 6+ years of hands‑on information security experience, with at least 2 years in a Security Operations Centre performing monitoring, detection engineering, and incident response.
  • Demonstrated hands‑on experience administering and tuning a SIEM platform — onboarding log sources, writing correlation rules and queries, and building dashboards.
  • Practical experience investigating and closing security incidents end to end, with clear written documentation and evidence handling.
  • Good working knowledge of IT infrastructure — networking, firewalls, servers, applications, and cloud — and how each generates security‑relevant telemetry.
  • Strong analytical and troubleshooting ability: structured, evidence‑led, and calm under pressure.
  • Clear written and verbal communication in English; ability to explain security risk to non‑technical clinical and administrative staff. Working knowledge of Malayalam is an advantage.
  • Willingness to provide on‑call cover and respond to security escalations outside normal working hours.
TECHNICAL SKILLS
  • SIEM — Microsoft Sentinel, Splunk, IBM QRadar, or a similar enterprise platform; comfortable with the platform's query language (KQL, SPL, AQL, or equivalent).
  • EDR / XDR — Microsoft Defender for Endpoint, CrowdStrike, Trend Micro, or a similar solution — deployment, policy configuration, detection triage, and response actions.
  • SOAR & Automation — Exposure to SOAR platforms and playbook automation; scripting in PowerShell, Python, or Bash for enrichment and routine tasks.
  • Networking — Strong understanding of TCP/IP, DNS, HTTP/HTTPS, VPN, firewalls, proxies, and network security concepts; ability to read packet captures and firewall logs.
  • Platforms & Identity — Working knowledge of Windows and Linux server and endpoint administration, Active Directory / Entra ID, business applications, and cloud environments (Azure, AWS, or GCP).
  • Threat Knowledge — Good understanding of common attack techniques and vulnerabilities, the MITRE ATT&CK framework, IOC analysis, and threat detection methodology.
  • Frameworks — Familiarity with NIST CSF or the NIST incident‑handling lifecycle, ISO 27001 controls, and ITIL incident management practices.
PREFERRED QUALIFICATIONS
  • Security certifications such as CompTIA Security+ or CySA+, EC-Council CEH, Microsoft SC‑200 or AZ‑500, Splunk Core Certified Power User, or GIAC (GCIA / GCIH).
  • Prior experience in a hospital, healthcare group, or other 24x7 mission‑critical environment.
  • Exposure to securing HIS/EMR, PACS, LIS, and connected medical devices, and to healthcare data standards (HL7, DICOM, FHIR) at a security‑analysis level.
  • Experience with digital forensics, malware analysis, or memory and disk artefact review.
  • Experience with cloud security posture management, DLP, CASB, or email security gateways.
  • Experience supporting ISO 27001, NABH, or regulatory audits with security evidence.
  • Exposure to vulnerability management platforms (Nessus, Qualys, Rapid7, or similar).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Engineer
SOC Engineer

Mintskill HR Solutions LLP • Mumbai

On-site
INR 600,000 - 1,000,000
Senior SOC Analyst/SOC Lead
Senior SOC Analyst/SOC Lead

NTT DATA BUSINESS SOLUTIONS • Hyderabad

Hybrid
INR 1,200,000 - 2,400,000
SISA Information Security - Security Operations Center Manager - SIEM/SOAR
SISA Information Security - Security Operations Center Manager - SIEM/SOAR

SISA • Bengaluru

On-site
INR 3,000,000 - 5,200,000
Security Operations Center Lead
Security Operations Center Lead

Altera • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Senior Security Engineer SOC
Senior Security Engineer SOC

42gears Mobility Systems • Bengaluru

On-site
INR 1,800,000 - 2,400,000
SOC Manager
SOC Manager

SISA • Bengaluru

On-site
INR 6,000,000 - 9,000,000
Technical Specialist - Cyber Security L3
Technical Specialist - Cyber Security L3

Lenovo • Bengaluru

On-site
INR 1,400,000 - 2,100,000
Group Security Operations Center Specialist
Group Security Operations Center Specialist

DP World • Bengaluru

On-site
INR 1,500,000 - 2,000,000
Junior Engineer
Junior Engineer

Lyric Exponentials India Private Limited • Hyderabad

Hybrid
INR 1,000,000 - 1,500,000
Information Security Engineer Lead
Information Security Engineer Lead

Callaway Digital Technologies • Hyderabad

Hybrid
INR 1,200,000 - 1,800,000