SOC L3 Expert

Maandag® Middle East

India

On-site

INR 800,000 - 1,200,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Maandag® Middle East is seeking an experienced SOC Analyst (L3) to join their Security Operations Center. This role entails alert validation, incident investigation, and threat containment in a hybrid IT environment.

The ideal candidate should have over 5 years of experience in security operations, strong hands-on skills with SIEM and EDR tools, and the ability to manage complex security events.

Qualifications

  • 5+ years of experience in a SOC, MDR, or Security Operations role.
  • Strong experience with SIEM and EDR tools.
  • Ability to write structured incident reports.

Responsibilities

  • Monitor and triage security alerts from various platforms.
  • Investigate attacker activities and contain threats.
  • Collaborate with senior SOC teams during major incidents.

Skills

SIEM tools
EDR solutions
Windows security knowledge
Incident response
Cyber threat analysis

Tools

Microsoft Sentinel
Splunk
QRadar
CrowdStrike

Job description

We are seeking an experienced SOC Analyst (L3) to join our internal Security Operations Center. This role focuses on in-depth alert validation, incident investigation, and threat containment across a hybrid IT and cloud environment. The analyst will handle complex security events, perform proactive threat hunting, and collaborate closely with senior responders and detection teams to continuously improve the organization’s security posture.

Primary Objectives
  • Validate and correlate security alerts to identify true security incidents
  • Investigate attacker activity to determine entry point, scope, impact, and timeline
  • Contain threats swiftly and provide clear remediation guidance
  • Escalate and coordinate with senior SOC / Incident Response teams during major incidents
  • Maintain detailed documentation and highlight visibility or detection gaps
  • Improve monitoring, detection quality, and response effectiveness across the SOC
Key Responsibilities
  • Monitor and triage security alerts from SIEM, EDR, NDR, and cloud security platforms
  • Perform deep-dive investigations across endpoint, network, identity, and cloud layers
  • Differentiate true positives vs false positives with strong analytical judgment
  • Execute initial incident response actions (containment, isolation, account blocking, etc.) using defined playbooks
  • Enrich alerts using threat intelligence, MITRE ATT&CK mapping, and contextual analysis
  • Investigate phishing, malware, ransomware, credential abuse, lateral movement, and persistence techniques
  • Analyze logs from Windows, Linux, firewalls, network devices, and cloud platforms
  • Conduct email header analysis and malware/software analysis (static and dynamic)
  • Perform proactive threat hunting across endpoint, network, and cloud telemetry
  • Maintain accurate incident timelines, evidence, and internal reports
  • Collaborate with Detection & Automation teams to reduce alert noise and enhance detection logic
  • Support 24/7 SOC operations in a rotational shift model, including nights and weekends
Required Experience & Qualifications
  • 5+ years of experience in a SOC, MDR, or Security Operations role
  • Strong hands-on experience with:
  • SIEM tools: Microsoft Sentinel, Splunk, QRadar, FortiSIEM (or equivalent)
  • EDR solutions: Microsoft Defender, CrowdStrike, Cortex XDR
  • Excellent knowledge of Windows security and Active Directory investigations, including:
  • Lateral movement and privilege escalation techniques
  • Solid understanding of:
  • Common attack techniques: phishing, malware, ransomware, credential theft, persistence
  • MITRE ATT&CK framework
  • TCP/IP, DNS, DHCP, HTTP/S
  • OSI model, routing, switching, common protocols
  • Experience analyzing process trees, command-line activity, parent/child processes
  • Working knowledge of Azure, AWS, and GCP security fundamentals
  • Ability to write clear, structured incident reports and summaries
  • Comfortable working under pressure during active security incidents
  • Willingness to work 24/7 rotational shifts including nights, weekends, and holidays
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

L3 SOC Analyst
L3 SOC Analyst

Envision Technology Solutions • India

Remote
INR 2,500,000 - 4,500,000
Security Analyst - L2
Security Analyst - L2

Nopal Cyber, LLC. • Hyderabad

On-site
INR 1,200,000 - 1,600,000
SOC L1 Analyst
SOC L1 Analyst

Verint • Bengaluru

On-site
INR 1,000,000 - 1,500,000
L3 SOC Analyst
L3 SOC Analyst

UST • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Junior Engineer
Junior Engineer

Lyric Exponentials India Private Limited • Hyderabad

On-site
INR 1,000,000 - 1,500,000
Lead SOC Analyst
Lead SOC Analyst

Sampoorna Consultants • Bengaluru

On-site
INR 1,000,000 - 1,500,000
SOC - Senior Associate L2
SOC - Senior Associate L2

Publicis Re:Sources • Gurugram District

On-site
INR 1,200,000 - 2,400,000
SOC - Senior Associate L2
SOC - Senior Associate L2

Publicis Re:Sources • Gurugram District

On-site
INR 1,200,000 - 2,400,000
SOC Analyst
SOC Analyst

AlifCloud IT Consulting Pvt. Ltd. • Maharashtra

On-site
INR 350,000 - 520,000
Soc Analyst
Soc Analyst

Bahwan CyberTek • Chennai District, Bengaluru

On-site
INR 600,000 - 900,000