Sr. Analyst - SOC

Darwinbox Digital Solutions Pvt. Ltd.

Pune District

On-site

INR 600,000 - 1,200,000

Full time

37 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Darwinbox Digital Solutions Pvt. Ltd. is seeking a vigilant SOC Analyst (L2) to manage 24x7 monitoring, triage, and incident response. You will analyze logs from SIEM, EDR/XDR, firewalls, cloud and identity sources, investigate incidents, and develop playbooks to improve detection and response.

You will collaborate with networks, servers, cloud, IAM and IT teams to contain and remediate threats, while producing RCA, timelines and security advisories for management.

Qualifications

  • Experience in L2 monitoring, triage, investigation and 24x7 SOC operations.
  • Proficient in log analysis from SIEM, EDR/XDR, firewalls, cloud and identity sources.
  • Strong incident response and RCA skills; familiar with IOCs and TTPs.
  • Scripting knowledge (Python/PowerShell/Bash) to automate SOC tasks.
  • Excellent written and verbal communication for incident reports and updates.

Responsibilities

  • Perform L2 monitoring, triage, investigation and response in a 24x7 SOC.
  • Analyze and correlate logs from SIEM, EDR/XDR, firewalls and cloud services.
  • Investigate malware, phishing, compromised accounts and unusual network activity.
  • Contribute to SOC playbooks, SOPs, dashboards, and knowledge bases.
  • Coordinate with cross-functional teams for containment and remediation.
  • Prepare incident reports, timelines, RCA, advisories and updates.

Job description

  • Perform L2 monitoring, triage, investigation, and response to security alerts and incidents in a 24x7 SOC environment.
  • Analyze and correlate logs from SIEM, EDR/XDR, firewalls, network devices, servers, cloud, identity, and security applications.
  • Investigate security incidents such as malware, phishing, compromised accounts, suspicious network activity, privilege escalation, lateral movement, and data exfiltration.
  • Conduct root-cause analysis, identify attack techniques/TTPs, and determine the scope and impact of incidents.
  • Perform threat hunting and proactively identify suspicious activities, IOCs, and emerging threats.
  • Create, validate, and tune SIEM correlation rules, detection use cases, and alerts based on organizational requirements.
  • Perform false-positive analysis and detection tuning to improve alert accuracy and SOC efficiency.
  • Analyze threat intelligence, vulnerabilities, IOCs, and TTPs and correlate them with internal security events.
  • Support investigation and response to critical and high-severity incidents, escalating complex cases to L3/Incident Response teams with complete evidence and analysis.
  • Coordinate with Network, Server, Cloud, IT, IAM, Vulnerability Management, and other technology teams for containment and remediation.
  • Monitor and validate the health and availability of critical security monitoring/log sources and report gaps or ingestion issues.
  • Prepare and maintain incident reports, investigation timelines, RCA, security advisories, and SOC documentation.
  • Maintain accurate incident records and updates on ServiceNow, ManageEngine or other ITSM platforms.
  • Develop and maintain SOC playbooks, SOPs, knowledge articles, and investigation procedures.
  • Use Python, PowerShell, Bash, or other scripting languages to automate repetitive SOC activities and analysis.
  • Perform basic network/packet analysis and investigate suspicious network communications.
  • Contribute to SOC dashboards, metrics, trend analysis, and management reporting.
  • Share investigation findings, threat intelligence, and lessons learned with other SOC analysts and security teams.
  • Continuously improve SOC detection coverage, incident response processes, monitoring capabilities, and operational efficiency.
Certification
  • Security certifications such as SC-200, Security+, CySA+, CEH, GCIH, GCIA, or equivalent are preferred.
Communication & Documentation
  • Strong written and verbal communication skills.
  • Ability to prepare clear incident reports, investigation summaries, RCA documents, security advisories, and management updates.
  • Ability to communicate technical security findings to both technical and non-technical stakeholders.
  • Ability to contribute to SOC documentation, playbooks, SOPs, dashboards, and knowledge repositories.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Analyst - L2
Security Analyst - L2

Nopal Cyber, LLC. • Hyderabad

On-site
INR 1,200,000 - 1,600,000
SOC L1 Analyst
SOC L1 Analyst

Verint • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Sr. Analyst - SOC
Sr. Analyst - SOC

Neurealm Company • Pune District

On-site
INR 900,000 - 1,500,000
SOC L3 Expert
SOC L3 Expert

Maandag® Middle East • India

On-site
INR 800,000 - 1,200,000
Lead SOC Analyst
Lead SOC Analyst

Sampoorna Consultants • Bengaluru

On-site
INR 1,000,000 - 1,500,000
L3 SOC Analyst
L3 SOC Analyst

UST • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Junior Engineer
Junior Engineer

Lyric Exponentials India Private Limited • Hyderabad

On-site
INR 1,000,000 - 1,500,000
SOC Engineer (L2)
SOC Engineer (L2)

PeopleStrong • Chennai District

On-site
INR 900,000 - 1,400,000
Soc Analyst
Soc Analyst

Capgemini • Pune District

Hybrid
INR 900,000 - 1,500,000
Information Security Specialist
Information Security Specialist

ZEISS India • Bengaluru

On-site
INR 800,000 - 1,200,000