Job Summary
Experience:
7.00 - 10.00 Years
Industrial Type:
IT-Software/Software Services
Location:
Bangalore
Functional Area:
IT Software - Other
Designation:
Lead SOC Analyst - AM - BLR / GGN
Key Skills:
soc analyst,EDR, SOAR,incident,
Educational Level:
Graduate/Bachelors
Job Post Date:
2026-09-07
Stream of Study:
Degree:
BE-Comp/IT, BE-Other, BTech-Comp/IT, BTech-Other, MBA, MCA
Company Description
Our Client in India is one of the leading providers of risk, financial services and business advisory, internal audit, corporate governance, and tax and regulatory services.
Our Client was established in India in September 1993, and has rapidly built a significant competitive presence in the country. The firm operates from its offices in Mumbai, Pune, Delhi, Kolkata, Chennai, Bangalore, Hyderabad , Kochi, Chandigarh and Ahmedabad, and offers its clients a full range of services, including financial and business advisory, tax and regulatory.
Our client has their client base of over 2700 companies. Their global approach to service delivery helps provide value-added services to clients. The firm serves leading information technology companies and has a strong presence in the financial services sector in India while serving a number of market leaders in other industry segments.
Job Description
Core Responsibilities
Incident Response & Investigation
• Perform triage, investigation, containment, and remediation activities for complex and high-severity cybersecurity incidents.
• Act as a senior technical escalation point during incident handling, providing guidance and direction to analysts as required.
• Participate in incident bridges, contributing clear technical updates and investigative findings.
• Conduct forensic data collection and analysis across endpoints, network, cloud, and identity sources.
• Produce accurate and well-structured incident timelines, investigation notes, and post-incident summaries.
• Support post-incident reviews by contributing technical insights and lessons learned.
Detection & Threat Monitoring
• Review and investigate alerts generated from SIEM, EDR, cloud security, and identity platforms.
• Support the tuning and refinement of detection rules to improve alert quality and reduce false positives.
• Conduct threat-hunting activities under defined hypotheses, using available telemetry and analytical techniques.
• Identify gaps in visibility or logging and raise these with senior analysts or engineering teams.
SOC Tooling & Automation Support
• Use SOC tooling effectively to support investigations and response activities.
• Contribute ideas and feedback to improve SOC workflows, automation and playbooks.
• Assist with the validation and testing of changes to SOC tools and automated response processes.
• Highlight tooling issues or limitations that impact investigation effectiveness.
Governance, Process & Assurance Support
• Support internal and external audit activities by providing investigation evidence and technical input when requested.
• Follow established SOC procedures and ensure investigations are documented accurately and consistently.
• Contribute to the maintenance of SOC documentation, playbooks and operational procedures.
• Participate in lessons-learned activities and contribute suggestions for process improvement.
Team & Stakeholder Interaction
• Provide informal guidance and support to junior analysts during investigations, helping to improve analysis quality.
• Share technical knowledge and investigative techniques with peers through day-to-day collaboration.
• Communicate technical findings clearly to SOC leads and relevant stakeholders during incidents.
• Work collaboratively with Legal, Risk, Privacy, Crisis Management and Global SOC teams when required.
Operational Support
• Support daily SOC monitoring activities during periods of increased workload or incident activity.
• Assist with escalation handling for complex alerts or investigations.
• Maintain a high standard of investigative quality and professional conduct during operational activity.
Required Skills & Experience
• Experience working in a SOC, incident response or cybersecurity investigation role.
• Strong understanding of common attack techniques, threat actor behaviours, and investigative methodologies.
• Ability to analyse security alerts and logs across SIEM, EDR, cloud, identity and network security tools.
• Experience with scripting or automation (e.g. Python, PowerShell) is advantageous.
• Familiarity with frameworks such as MITRE ATT&CK, NIST CSF, or equivalent.
• Strong written and verbal communication skills, with the ability to explain technical findings clearly.
• Ability to work effectively under pressure during incident scenarios.
Preferred Qualifications
• Relevant industry certifications such as CompTIA CySA+ or Microsoft Certified:
• Security Operations Analyst Associate (SC-200).
• Hands-on experience with EDR, SOAR, or forensic tooling.
• Experience participating in threat-hunting activities or security exercises.
• Exposure to tabletop or incident-response simulations.
• Certifications or demonstrated expertise in Microsoft security technologies related to Sentinel, Purview, or Microsoft Defender suites (e.g., Microsoft Certified: Information Protection Administrator Associate (SC-400), Microsoft Certified: Azure Security Engineer Associate (AZ-500)).


