SOC L3 Expert

Maandag® Middle East

India

On-site

INR 800,000 - 1,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Maandag® Middle East is seeking an experienced SOC Analyst (L3) to join their Security Operations Center. This role entails alert validation, incident investigation, and threat containment in a hybrid IT environment.

The ideal candidate should have over 5 years of experience in security operations, strong hands-on skills with SIEM and EDR tools, and the ability to manage complex security events.

Qualifications

  • 5+ years of experience in a SOC, MDR, or Security Operations role.
  • Strong experience with SIEM and EDR tools.
  • Ability to write structured incident reports.

Responsibilities

  • Monitor and triage security alerts from various platforms.
  • Investigate attacker activities and contain threats.
  • Collaborate with senior SOC teams during major incidents.

Skills

SIEM tools
EDR solutions
Windows security knowledge
Incident response
Cyber threat analysis

Tools

Microsoft Sentinel
Splunk
QRadar
CrowdStrike

Job description

We are seeking an experienced SOC Analyst (L3) to join our internal Security Operations Center. This role focuses on in-depth alert validation, incident investigation, and threat containment across a hybrid IT and cloud environment. The analyst will handle complex security events, perform proactive threat hunting, and collaborate closely with senior responders and detection teams to continuously improve the organization’s security posture.

Primary Objectives
  • Validate and correlate security alerts to identify true security incidents
  • Investigate attacker activity to determine entry point, scope, impact, and timeline
  • Contain threats swiftly and provide clear remediation guidance
  • Escalate and coordinate with senior SOC / Incident Response teams during major incidents
  • Maintain detailed documentation and highlight visibility or detection gaps
  • Improve monitoring, detection quality, and response effectiveness across the SOC
Key Responsibilities
  • Monitor and triage security alerts from SIEM, EDR, NDR, and cloud security platforms
  • Perform deep-dive investigations across endpoint, network, identity, and cloud layers
  • Differentiate true positives vs false positives with strong analytical judgment
  • Execute initial incident response actions (containment, isolation, account blocking, etc.) using defined playbooks
  • Enrich alerts using threat intelligence, MITRE ATT&CK mapping, and contextual analysis
  • Investigate phishing, malware, ransomware, credential abuse, lateral movement, and persistence techniques
  • Analyze logs from Windows, Linux, firewalls, network devices, and cloud platforms
  • Conduct email header analysis and malware/software analysis (static and dynamic)
  • Perform proactive threat hunting across endpoint, network, and cloud telemetry
  • Maintain accurate incident timelines, evidence, and internal reports
  • Collaborate with Detection & Automation teams to reduce alert noise and enhance detection logic
  • Support 24/7 SOC operations in a rotational shift model, including nights and weekends
Required Experience & Qualifications
  • 5+ years of experience in a SOC, MDR, or Security Operations role
  • Strong hands-on experience with:
  • SIEM tools: Microsoft Sentinel, Splunk, QRadar, FortiSIEM (or equivalent)
  • EDR solutions: Microsoft Defender, CrowdStrike, Cortex XDR
  • Excellent knowledge of Windows security and Active Directory investigations, including:
  • Lateral movement and privilege escalation techniques
  • Solid understanding of:
  • Common attack techniques: phishing, malware, ransomware, credential theft, persistence
  • MITRE ATT&CK framework
  • TCP/IP, DNS, DHCP, HTTP/S
  • OSI model, routing, switching, common protocols
  • Experience analyzing process trees, command-line activity, parent/child processes
  • Working knowledge of Azure, AWS, and GCP security fundamentals
  • Ability to write clear, structured incident reports and summaries
  • Comfortable working under pressure during active security incidents
  • Willingness to work 24/7 rotational shifts including nights, weekends, and holidays
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst - L2
Security Analyst - L2

Nopal Cyber, LLC. • Hyderabad

On-site
INR 1,200,000 - 1,600,000
SOC L1 Analyst
SOC L1 Analyst

Verint • Bengaluru

On-site
INR 1,000,000 - 1,500,000
SOC L3 Analyst
SOC L3 Analyst

Isix • India

On-site
INR 2,500,000 - 4,500,000
SOC Analyst L2
SOC Analyst L2

Keka Technologies Private Limited • Gurugram District

On-site
INR 1,200,000 - 2,500,000
SOC Analyst – L3
SOC Analyst – L3

Ishan Technologies • Ahmedabad District

On-site
INR 1,200,000 - 1,800,000
L3 SOC Analyst
L3 SOC Analyst

UST • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Junior Engineer
Junior Engineer

Lyric Exponentials India Private Limited • Hyderabad

Hybrid
INR 1,000,000 - 1,500,000
Sr SOC Analyst - CyberAxis
Sr SOC Analyst - CyberAxis

Cyberaxislabs • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Soc Analyst
Soc Analyst

Incedo • Gurugram District

On-site
INR 1,800,000 - 2,400,000
24x7 Rotational Shift
Willingness to work on weekends/holid-
Technical Specialist - Cyber Security L3
Technical Specialist - Cyber Security L3

Lenovo • Bengaluru

On-site
INR 1,400,000 - 2,100,000