Sr. Security Operations Analyst

ShyftLabs

Dadri

On-site

INR 1,500,000 - 2,600,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ShyftLabs is seeking a highly technical Sr. Security Operations Analyst to join its Information Security team. You will design automated playbooks, tune telemetry across SIEM/EDR and cloud environments, and lead containment of high-severity incidents to mature our SOC.

You will define triage standards, perform threat hunting, and drive continuous improvement through post-incident reviews and metrics tracking such as MTTR and false-positive reduction.

Qualifications

  • Bachelor's degree in Cybersecurity, IT, or related field or equivalent hands-on experience.
  • Hands-on monitoring and investigation of alerts using SIEM and EDR platforms.
  • Strong written communication for case documentation and handoffs.

Responsibilities

  • Detection engineering: architect and optimize real-time playbooks across SIEM/EDR and cloud security.
  • Investigation: correlate findings and document timely case notes for alerts.
  • Incident command: lead response for high-severity incidents with cross-functional teams.
  • Containment: execute actions per playbooks including endpoint isolation and blocking indicators.
  • Threat hunting: research indicators of compromise to identify anomalies.
  • Rule tuning: adjust rules to reduce false positives and close visibility gaps.
  • Email threats: investigate phishing and BEC and remediate threats.
  • Continuous improvement: contribute to post-incident reviews and metrics.
  • Currency: stay current on MITRE ATT&CK and evolving threats.

Skills

SIEM platforms
EDR platforms
Threat hunting
Log analysis
Incident response
Written communication
Case documentation
Detection engineering

Education

Bachelor's degree in Cybersecurity or related field

Tools

Splunk
Microsoft Sentinel
QRadar
CrowdStrike
Defender for Endpoint
SentinelOne
Windows
Linux

Job description

Role Overview

We are seeking a highly technical and proactive Sr. Security Operations Analyst to join our Information Security team. In this role you will engineer and mature our security operations infrastructure - designing automated playbooks, tuning advanced telemetry across SIEM, EDR, and cloud environments, and leading high-severity incident containment. As a senior member of the team, you will define triage standards and elevate the technical capability of the wider SOC.

Responsibilities
  • Detection engineering: Architect and optimize real-time detection engineering playbooks across SIEM, EDR, and cloud security platforms to minimize false positives, accelerate triage, and scale threat-hunting capability.
  • Investigation: Investigate suspicious activity, correlate findings across data sources, and document clear, timely case notes for each alert or incident.
  • Incident command: Lead the response lifecycle for high-severity incidents as primary investigator or incident commander, ensuring seamless coordination and technical handoff across cross-functional teams.
  • Containment: Execute containment actions under established playbooks, including endpoint isolation, disabling compromised accounts, and blocking malicious indicators.
  • Threat hunting: Research indicators of compromise and apply threat intelligence to identify anomalous behavior.
  • Rule tuning: Tune detection rules and use cases to reduce false positives and close visibility gaps, in coordination with engineering.
  • Email threats: Investigate and remediate email-based threats such as phishing and business email compromise, from both user submissions and automated detection.
  • Continuous improvement: Contribute to post-incident reviews and metrics reporting - MTTD, MTTR, alert volume, and false-positive rate - to support ongoing SOC maturity.
  • Currency: Stay current on emerging threats, attacker TTPs, and industry frameworks such as MITRE ATT&CK.
Requirements
  • SIEM platforms
  • Splunk
  • Microsoft Sentinel
  • QRadar
  • EDR platforms
  • CrowdStrike
  • Microsoft Defender for Endpoint
  • SentinelOne
  • Windows operating systems
  • Linux operating systems
  • TCP/IP
  • DNS
  • Firewalls
  • Network proxies
  • Incident response
  • Threat hunting
  • Detection engineering
  • Log analysis
  • MITRE ATT&CK framework
  • Phishing investigation
  • Business email compromise
  • Written communication
  • Case documentation
Preferred Skills
  • AWS
  • Azure
  • GCP
  • Cloud security
  • SOAR platforms
  • Python
  • PowerShell
  • KQL
  • SPL
  • Security automation
  • Playbook development
Qualifications
  • 4-6 years of IT or security experience, including hands-on exposure to a SOC, security help desk, or systems administration environment
  • 3+ years monitoring or investigating alerts using a SIEM (e.g., Splunk, Sentinel, QRadar) and an EDR platform (e.g., CrowdStrike, Defender for Endpoint, SentinelOne)
  • Working knowledge of Windows and Linux operating systems, including common attack surfaces and log sources such as event logs, auth logs, and process telemetry
  • Foundational understanding of networking concepts (TCP/IP, DNS, proxies, firewalls) and the protocols relevant to intrusion detection
  • Strong attention to detail, sound judgment under time pressure, and clear written communication for case documentation and shift handoffs
  • Ability to work effectively in a 24/7 SOC rotation, including scheduled shifts and periodic on-call coverage
  • Bachelor's degree in Cybersecurity, Information Technology, or a related field - or equivalent hands-on experience
  • Foundational certifications such as CompTIA Security+ or CySA+ are expected; progress toward GIAC (GCIH, GFACT) or similar is a plus
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Security Operations Analyst
Sr. Security Operations Analyst

Simfluent • Dadri

On-site
INR 1,200,000 - 1,800,000
Security Analyst
Security Analyst

Access Healthcare • Zone 7 Ambattur

On-site
INR 1,200,000 - 2,100,000
Soc Analyst
Soc Analyst

BUSINESSNEXT • Dadri

On-site
INR 1,200,000 - 2,000,000
Senior Security Operations Center (SOC) Analyst
Senior Security Operations Center (SOC) Analyst

Intuitive Apps • Mumbai

On-site
INR 1,500,000 - 2,300,000
Sr. SOC Analyst
Sr. SOC Analyst

Ferfier Technologies • Dadri

Hybrid
INR 1,500,000 - 2,100,000
Flexible/Remote work
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Dun & Bradstreet • Hyderabad

Hybrid
INR 2,500,000 - 4,500,000
Junior Engineer
Junior Engineer

Lyric Exponentials India Private Limited • Hyderabad

Hybrid
INR 1,000,000 - 1,500,000
Senior Security Analyst
Senior Security Analyst

UltraViolet Cyber • Hyderabad

On-site
INR 800,000 - 1,200,000
Information Security Engineer Lead
Information Security Engineer Lead

Callaway Digital Technologies • Hyderabad

Hybrid
INR 1,200,000 - 1,800,000
Senior SOC L3 Analyst
Senior SOC L3 Analyst

Opt IT • India

On-site
INR 1,800,000 - 3,600,000