Technical Specialist - Cyber Security L3

Lenovo

Bengaluru

On-site

INR 1,400,000 - 2,100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Lenovo is seeking a SOC Analyst to be on the front lines of cyber defense. The role involves detection, containment, and remediation of IT threats across enterprise environments.

Responsibilities include developing SIEM queries, playbooks, and dashboards; aligning detections with MITRE ATT&CK; and providing in-depth incident analysis and client-focused reporting. Strong expertise in SIEM/EDR is required.

Qualifications

  • Experience in detection and incident response for enterprise security environments.
  • Ability to develop and tune SIEM queries and playbooks.
  • Knowledge of MITRE ATT&CK framework and its application to detections.
  • Strong analytical skills for root cause and trend analysis.
  • Experience with log sources: network, host, firewall, and security appliances.
  • Hands-on with EDR, UEBA, and related SOC tooling.
  • Ability to document findings, actions, and outcomes clearly.
  • Familiarity with threat hunting concepts and data analysis.
  • Capable of driving automation for playbooks and detections.
  • Excellent communication for stakeholders and customers.

Responsibilities

  • Operate as a detection and incident response SME for SOC.
  • Develop custom queries and playbooks for investigations.
  • Align detection capabilities to the MITRE ATT&CK framework.
  • Perform root cause analyses of detection failures.
  • Drive continuous development of SOC detection capabilities.
  • Manage and resolve complex issues with security tooling.
  • Configure SIEM and SOC tools per policy and governance.
  • Support Threat Hunters with data analysis.
  • Provide escalation for SOC/security incidents.
  • Ensure tools comply with governance and policies.
  • Contribute to policy, procedure, and process documentation.
  • Define governance for security tooling incl. SIEM/EDR.
  • Create and review detection designs for new threats.
  • Identify automation opportunities from incidents.
  • Advise clients on mitigating suspicious activity.
  • Provide in-depth incident analysis to users/customers.
  • Prepare SOC management and periodic reports.
  • Analyze device logs and generate client-specific reports.
  • Create client-facing queries for real-time alerts.
  • Analyze network/host logs to determine remediation steps.
  • Contain, analyze, and eradicate malicious activity.
  • Oversee patch and security management tasks.
  • Review CMDB entries for accuracy.
  • Suggest process improvements and best practices.
  • Lead or participate in projects and customer engagements.
  • Maintain strong customer relationships.
  • Collaborate in virtual/global teams.

Skills

Threat & vulnerability analysis
SOC/SIEM expertise
Incident response
Root cause analysis
KQL / query development
EDR/UEBA tools
Documentation & reporting
Networking knowledge
Automation opportunities
Threat hunting support
Mitre ATT&CK alignment
Security tooling management

Tools

SIEM
EDR
NDR
UEBA

Job description

Security Operations Centre (SOC) Analyst plays a vital role in Security delivery. As a SOC Analyst Level 3, you will be on the front line of Cyber Defense, detecting & responding to Cyber Incidents as they happen. You will work with other team members to provide situational awareness through detection, containment, and remediation of IT threats. This job requires great attention to detail and general awareness of Cyber Security tools like SIEM, XDR, EDR, IDS/ IPS, ability understand various logs - network logs, sys logs, Firewall logs. As a SOC Analyst you are expected to have working knowledge in areas of networking, malware analysis, incident response, vulnerability management.

  • * Threat & vulnerability analysis
  • * Investigate, document & report Information security issues & emerging trends
  • * Analysis & response to unknown vulnerabilities
Responsibilities:

As a SOC Analyst - Level 3, you will:

  • * Operate as detection and security incident response subject-matter expert
  • * Technical subject-matter expert in SOC/ SIEM and supporting technologies (EDR, UEBA, etc.) to develop custom queries (e.g., KQL) and playbooks for the SOC analysts to utilize in their investigations.
  • * Align and maintain detection capability to the Mitre attack framework.
  • * Perform root cause analysis of detection failures, identify areas for improvement.
  • * Drive the continuous development of detection capability for SOC
  • * Manage, investigate, and resolve complex issues with the Security tooling.
  • * Securely configure the SIEM, and other SOC solutions in accordance with relevant policy and regulation
  • * Support the Threat hunters in executing complex data analysis.
  • * Provide a point of escalation for SOC/ security detection technical service issues.
  • * Ensure the relevant security tools are compliant with company standards and governance.
  • * Contribute to existing Policy, procedures and process documentation enhancements
  • * Define and implement technical governance processes for security tooling of SOC, SIEM and other security tools including AV, EDR, Defender Cloud.
  • * Create and review detection technology high and low level designs.
  • * Propose and identify automation opportunities resulting from incidents;
  • * Provide recommendations to the Client team, on how to mitigate or avert the occurrence of any suspicious activity within their environment.
  • * Provide In depth analysis to the user/customer about the security incidents (eg. Phishing attack)
  • * Prepare SOC Management Reports.
  • * Analyzing & preparing daily and monthly reports based on the devices which are being monitored
  • * Creating Reports and Dashboards based on the customer requirement.
  • * Creating Queries for the Rules requested by client for real time alerts.
  • * Creating Reports which helps in providing the logs for the alerts, for finding any possible threats.
  • * Analyze a variety of network and host-based security appliance logs (Firewalls, NIDS, HIDS, Sys Logs, etc.) to determine the correct remediation actions and escalation paths.
  • * Independently follow procedures to contain, analyze, and eradicate malicious activity.
  • * Change Management/ Implementation: Independently implement changes to meet customer infrastructure needs within area of technical responsibility
  • * Patch and Security Management: Apply patch and security changes per policy.
  • * Configuration Management: Review Configuration Management Database (CMDB) entries to ensure they are complete and accurate.
  • * Quality: Provide continual improvement recommendations for direct responsibility area (process improvement, technical standard updates, etc).
  • * Project Management: Lead & participate in customer and internal projects, including transformation.
  • * Customer Relationship Management: Set expectations with customers and/or internal businesses/end users within defined parameters.
  • * Teamwork: Work as part of a team, which may be virtual and/or global. Participate as part of a team and maintains good relationships with team members and customers
Skill:

8 - 12 years of relevant experience

Typical skills include:
  • * Fine-tune SIEM and other SOC tooling to exclude noise and false positives
  • * Create and fine-tune content in SIEM - correlation rules, Dashboard and Reports etc
  • * Interact with SIEM, EDR and NDR vendors (TAC Support) to remediate any issues with tooling
  • * Evaluate new solutions for SOC
  • * Identify opportunities to improve overall capacity, playbook and runbook
  • * Understanding of threat landscapes and threat modelling, security threat and vulnerability management, and security monitoring
  • * Working knowledge of tools and techniques used by attackers to gain entry into corporate networks, including common IT system flaws and vulnerabilities.
  • * Knowledge of industry standards such as ISO 27001, HIPAA, FedRAMP, Cloud Security Alliance, NIST frameworks and risk methodologies
  • * Demonstrated experience in communicating complex security concepts, both verbally and in writing, to a variety of audiences
  • * Must take ownership of tasks and demonstrate high degree of autonomy to ensure completion
  • * Excellent understanding of related technologies (Networking, Operating Systems)
  • * General Project Management (Expert)
  • * Business Analysis (Expert)
  • * Has ability to perform/drive resolution of problems on individual products.
  • * Able to communicate broad and specific concepts with team and to peers.
  • * Able to produce documentation for use by team and customer.
  • * Able to perform/drive resolution of problems on combinations and interactions of products
  • * Proactive approach to meet & exceed goals
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security - Subject Matter Expert
Cyber Security - Subject Matter Expert

Lenovo • Bengaluru Urban

On-site
INR 1,500,000 - 2,500,000
L3 SOC Analyst
L3 SOC Analyst

UST • Bengaluru

On-site
INR 1,500,000 - 2,100,000
SOC-Associate Director
SOC-Associate Director

SISA • Bengaluru

On-site
INR 1,000,000 - 1,500,000
SOC L3 Expert
SOC L3 Expert

Maandag® Middle East • India

On-site
INR 800,000 - 1,200,000
Sr. SOC Engineer (L3)
Sr. SOC Engineer (L3)

PeopleStrong • Chennai District

On-site
INR 1,800,000 - 2,600,000
Security Analyst - L2
Security Analyst - L2

Nopal Cyber, LLC. • Hyderabad

On-site
INR 1,200,000 - 1,600,000
Junior Engineer
Junior Engineer

Lyric Exponentials India Private Limited • Hyderabad

Hybrid
INR 1,000,000 - 1,500,000
L2 SOC Analyst
L2 SOC Analyst

UST • Thiruvananthapuram

Hybrid
INR 600,000 - 900,000
Expert IT Cyber Defense Analyst
Expert IT Cyber Defense Analyst

Jobtailor • Pune District

On-site
INR 900,000 - 1,500,000
SOC Analyst – L3
SOC Analyst – L3

Ishan Technologies • Ahmedabad District

On-site
INR 1,200,000 - 1,800,000