SOC- IR | Sr. Analyst -(CEH, LogRhythm/CompTIA Security+, ECSA,)

Deloitte Shared Services India

Mumbai, Hyderabad

On-site

INR 900,000 - 1,300,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Deloitte Shared Services India is seeking an experienced SOC Analyst to monitor security events and drive incident response. You will triage alerts, perform log analysis, and coordinate with L2/L3 teams to mitigate threats using SIEM and EDR/XDR tools.

The role requires 1–3 years in SOC, relevant certifications, and strong TCP/IP/log-analysis skills. Office-based role with Hyderabad and Mumbai locations.

Qualifications

  • 1–3 years in SOC or cybersecurity operations
  • Certifications: CompTIA Security+ / CEH / ECSA / OEM- LogRhythm
  • Experience with TCP/IP and log analysis

Responsibilities

  • Investigate security alerts from SOC L1 using SIEM/EDR/XDR and related platforms.
  • Analyze security events for scope, impact, and root cause.
  • Validate true positives and reduce false positives through log analysis.
  • Classify incidents by severity and business impact.
  • Coordinate containment, eradication, and recovery per IR procedures.
  • Escalate complex incidents to L2/L3 when needed.
  • Investigate IOC indicators (IPs, URLs, domains, hashes).
  • Correlate events across technologies to detect sophisticated attacks.

Skills

SOC monitoring
Security operations
Incident triage
Cybersecurity operations
SIEM tools
EDR/XDR
Threat intel
Log analysis
TCP/IP analysis
Clear communication

Education

Bachelors/Masters in CS or InfoSec

Tools

LogRhythm
Splunk
Microsoft Defender
Cortex XDR
CrowdStrike
Sentinel
Chronicle

Job description

Role & responsibilities
  • 1- 3 years of experience in SOC monitoring, security operations, incident triage, or cybersecurity operations.
  • Please apply only if you hold at least one of the following Valid certifications: CompTIA Security+ / CEH / ECSA /OEM - LogRhythm certification .
  • Should be working in SOC, SIEM technologies (LogRhythm, Splunk, Sentinel, Chronicle)
  • EDR/XDR solutions (CrowdStrike, Cortex XDR, Microsoft Defender)
  • Triage, analyze & respond to SIEM events with articulate analysis and clear response guidance/questions to other teams through established collaboration mechanisms (Ticketing systems, Mails)
  • Leverage the Operational & Tactical Threat Intel data from the established feeds & sources to detect Threats
  • Ability to efficiently utilize to log analytics and usage of SIEM for analyzing & filtering logs. Recorded Future Fusion, Brand protection cloud side.
  • Optimizes threat detection products for data security information and event management (SIEM), advanced email protection, endpoint detection and response (EDR), antivirus, intrusion detection systems, firewalls, proxies, and other industry standard security technologies.
  • Works closely with Level 2 & Level 3 team towards the continuous improvement of the service
  • Should have expertise on TCP/IP network traffic and event log analysis.
  • Having strong perseverance to keep the Incident response actions focused & progressed.
  • Ability to effectively communicate (orally & written) complex technical issues to a diverse set of audience that include technical, non-technical & executive level staff.
  • Bachelors or Masters degree in Computer Science, Information Security, or related field.
  • Professional is required to work from office
  • Job location : Hyderabad, Mumbai
Preferred candidate profile
  • Investigate security alerts escalated by SOC L1 using SIEM, EDR, XDR, UEBA, NDR, Email Security, and other security platforms.
  • Perform in-depth analysis of security events to determine scope, impact, and root cause.
  • Validate true positives and eliminate false positives through detailed log analysis.
  • Classify incidents based on severity and business impact.
  • Execute containment, eradication, and recovery activities as per incident response procedures.
  • Escalate complex incidents to L2/ L3 or Incident Response teams when required.
  • Analyze indicators of compromise (IOCs) including IPs, URLs, domains, file hashes, and email artifacts.
  • Correlate events across multiple security technologies to identify sophisticated attacks.
  • Identify malicious behavior using the MITRE ATT&CK framework and Cyber Kill Chain.
  • Investigate phishing, malware, ransomware, insider threats, privilege misuse, and suspicious authentication activities.
  • Perform endpoint investigations using EDR/XDR platforms.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Analyst - SOC
Senior Analyst - SOC

SHI • Hyderabad

On-site
INR 900,000 - 1,300,000
SISA Information Security - Security Operations Center Manager - SIEM/SOAR
SISA Information Security - Security Operations Center Manager - SIEM/SOAR

SISA • Bengaluru

On-site
INR 3,000,000 - 5,200,000
SOC SIEM Analyst
SOC SIEM Analyst

Deloitte Shared Services India • Nagpur District

On-site
INR 1,200,000 - 2,000,000
Security Operations Center Analyst - L2 || Mumbai || Only Immediate Joiner
Security Operations Center Analyst - L2 || Mumbai || Only Immediate Joiner

Innova ESI • Mumbai

On-site
INR 800,000 - 1,200,000
Cyber Security Threat Hunter - L3
Cyber Security Threat Hunter - L3

SHI • Hyderabad

On-site
INR 400,000 - 700,000
Sr. SOC Analyst
Sr. SOC Analyst

Systems Plus Pvt. Ltd. • Pune District

On-site
INR 1,800,000 - 3,200,000
IT&Data Sr. Product Analyst CERT Asia
IT&Data Sr. Product Analyst CERT Asia

Infosys • Hyderabad

On-site
INR 1,800,000 - 2,400,000
Security Architect
Security Architect

Accenture in India • Hyderabad

On-site
INR 1,500,000 - 2,100,000
Lead SOC Analyst
Lead SOC Analyst

Sampoorna Consultants • Bengaluru

On-site
INR 1,000,000 - 1,500,000
SOC Engineer (L2)
SOC Engineer (L2)

PeopleStrong • Chennai District

On-site
INR 900,000 - 1,400,000