Sr. Security Operations Analyst

Simfluent

Dadri

On-site

INR 1,200,000 - 1,800,000

Full time

35 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Simfluent is seeking a highly technical Sr. Security Operations Analyst to join our Information Security team in India.

You will engineer and mature our security operations infrastructure, designing automated playbooks and tuning telemetry across SIEM, EDR, and cloud environments while leading high-severity incident containment. You will define triage standards, elevate the technical capability of the SOC, and drive continuous improvement through post-incident reviews and metrics.

Qualifications

  • 4–6 years of IT or security experience in SOC/IT environment.
  • 3+ years monitoring or investigating alerts using a SIEM and an EDR platform.

Responsibilities

  • Architect and optimize real-time SIEM/EDR and cloud security playbooks.
  • Investigate suspicious activity and document case notes.
  • Lead high-severity incident containment as incident commander.
  • Contain threats via playbooks: endpoint isolation, disable accounts, block indicators.
  • Conduct threat hunting and apply threat intelligence.
  • Tune rules to reduce false positives and close gaps.
  • Investigate and remediate email threats like phishing and BEC.
  • Contribute to post-incident reviews and metrics (MTTD/MTTR).
  • Stay current on threats and MITRE ATT&CK.

Skills

SIEM platforms
Splunk
Microsoft Sentinel
QRadar
EDR platforms
CrowdStrike
Microsoft Defender for Endpoint
SentinelOne
Windows operating systems
Linux operating systems
TCP/IP
DNS
Firewalls
Network proxies
Incident response
Threat hunting
Detection engineering
Log analysis
MITRE ATT&CK framework
Phishing investigation
Business email compromise
Written communication
Case documentation

Education

Bachelor's degree in Cybersecurity, Information Technology, or a related field
Hands-on experience in security operations
Foundational certifications such as CompTIA Security+ or CySA+

Tools

Python
PowerShell
KQL
SPL
AWS
Azure
GCP
SOAR platforms
Playbook development

Job description

We are seeking a highly technical and proactive Sr. Security Operations Analyst to join our Information Security team. In this role you will engineer and mature our security operations infrastructure — designing automated playbooks, tuning advanced telemetry across SIEM, EDR, and cloud environments, and leading high-severity incident containment. As a senior member of the team, you will define triage standards and elevate the technical capability of the wider SOC.

Responsibilities
  • Detection engineering: Architect and optimize real-time detection engineering playbooks across SIEM, EDR, and cloud security platforms to minimize false positives, accelerate triage, and scale threat-hunting capability
  • Investigation: Investigate suspicious activity, correlate findings across data sources, and document clear, timely case notes for each alert or incident
  • Incident command: Lead the response lifecycle for high-severity incidents as primary investigator or incident commander, ensuring seamless coordination and technical handoff across cross-functional teams
  • Containment: Execute containment actions under established playbooks, including endpoint isolation, disabling compromised accounts, and blocking malicious indicators
  • Threat hunting: Research indicators of compromise and apply threat intelligence to identify anomalous behavior
  • Rule tuning: Tune detection rules and use cases to reduce false positives and close visibility gaps, in coordination with engineering
  • Email threats: Investigate and remediate email-based threats such as phishing and business email compromise, from both user submissions and automated detection
  • Continuous improvement: Contribute to post-incident reviews and metrics reporting — MTTD, MTTR, alert volume, and false-positive rate — to support ongoing SOC maturity
  • Currency: Stay current on emerging threats, attacker TTPs, and industry frameworks such as MITRE ATT&CK
Requirements
  • SIEM platforms
  • Splunk
  • Microsoft Sentinel
  • QRadar
  • EDR platforms
  • CrowdStrike
  • Microsoft Defender for Endpoint
  • SentinelOne
  • Windows operating systems
  • Linux operating systems
  • TCP/IP
  • DNS
  • Firewalls
  • Network proxies
  • Incident response
  • Threat hunting
  • Detection engineering
  • Log analysis
  • MITRE ATT&CK framework
  • Phishing investigation
  • Business email compromise
  • Written communication
  • Case documentation
Preferred Skills
  • AWS
  • Azure
  • GCP
  • Cloud security
  • SOAR platforms
  • Python
  • PowerShell
  • KQL
  • SPL
  • Security automation
  • Playbook development
Qualifications
  • 4–6 years of IT or security experience, including hands‑on exposure to a SOC, security help desk, or systems administration environment
  • 3+ years monitoring or investigating alerts using a SIEM (e.g., Splunk, Sentinel, QRadar) and an EDR platform (e.g., CrowdStrike, Defender for Endpoint, SentinelOne)
  • Working knowledge of Windows and Linux operating systems, including common attack surfaces and log sources such as event logs, auth logs, and process telemetry
  • Foundational understanding of networking concepts (TCP/IP, DNS, proxies, firewalls) and the protocols relevant to intrusion detection
  • Strong attention to detail, sound judgment under time pressure, and clear written communication for case documentation and shift handoffs
  • Ability to work effectively in a 24/7 SOC rotation, including scheduled shifts and periodic on‑call coverage
  • Bachelor's degree in Cybersecurity, Information Technology, or a related field — or equivalent hands‑on experience
  • Foundational certifications such as CompTIA Security+ or CySA+ are expected; progress toward GIAC (GCIH, GFACT) or similar is a plus

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Analyst
Senior Security Analyst

UltraViolet Cyber • Hyderabad

On-site
INR 800,000 - 1,200,000
Senior Security Operations Center (SOC) Analyst
Senior Security Operations Center (SOC) Analyst

Intuitive Apps • Mumbai

On-site
INR 1,500,000 - 2,300,000
Soc Engineer
Soc Engineer

Parkar Global Technologies • Ahmedabad District

On-site
INR 1,200,000 - 1,900,000
Associate SOC
Associate SOC

Epsilon Data Management • Bengaluru

On-site
INR 900,000 - 1,500,000
Cybersecurity Analyst
Cybersecurity Analyst

Abacus • Chennai District

On-site
INR 900,000 - 1,400,000
Junior Engineer
Junior Engineer

Lyric Exponentials India Private Limited • Hyderabad

Hybrid
INR 1,000,000 - 1,500,000
Cyber Security Analyst (SOC)
Cyber Security Analyst (SOC)

Genpact • Pune District

On-site
INR 900,000 - 1,500,000
Sr. Consultant
Sr. Consultant

Tribastion Technologies Pvt. Ltd. • India

On-site
INR 1,000,000 - 1,500,000
L2 SOC Analyst
L2 SOC Analyst

UST • Bengaluru

On-site
INR 1,400,000 - 2,200,000
Expert IT Cyber Defense Analyst
Expert IT Cyber Defense Analyst

Jobtailor • Pune District

On-site
INR 900,000 - 1,500,000