Overview
As an L2 SOC Analyst, you will monitor and triage security alerts, respond to escalations from Wrike's 24/7 MDR partner, investigate incidents end-to-end, and mature detection capabilities in a hybrid security model protecting Wrike and its customers.
What you'll do
- Monitor, triage, and investigate security alerts and events, including direct escalations from the 24/7 MDR partner Rapid7.
- Assess the risk and impact of potential incidents.
- Conduct end-to-end investigations, including log analysis, endpoint forensics, and scoping.
- Take swift remediation actions.
- Participate in the SOC on-call rotation to guarantee round-the-clock escalation coverage.
- Continuously refine and tune detection rules to minimize false positives and identify genuine threats faster.
- Contribute to threat hunting initiatives across endpoints, identity providers, SaaS platforms, and cloud environments.
- Help document, refine, and optimize SOC playbooks, runbooks, incident reports, and operational escalation workflows.
What you'll need
- 2–3+ years of hands-on experience in a SOC or security monitoring environment, including alert triage, incident investigation, and response.
- Hands-on experience with SIEM platforms, including Rapid7 InsightIDR or similar.
- Hands-on experience with EDR/antimalware tooling for endpoint investigations.
- Strong understanding of network security fundamentals, common threat vectors, and attack frameworks including MITRE ATT&CK.
- Sharp logical thinking and analytical skills.
- Advanced written and verbal English communication abilities.
- Ability and willingness to participate in an on-call rotation, including occasional nights and weekends.
Nice to have
- Prior experience collaborating directly with an MDR or MSSP partner in a hybrid SOC environment.
- Hands-on familiarity with tools such as Splunk, Wazuh, Microsoft Defender for Endpoint, Crowdtrike, Okta, Google Workspace, AWS, or GCP.
- Previous experience in active threat hunting, detection engineering, or task automation using Python/Bash.
- Relevant security certifications, such as Security+, CySA+, GCIH, GCDA, or vendor-specific certifications.
Details
- Location: Bangalore.
- Hybrid working model.
- Employees located near the Bangalore hub are generally expected to collaborate in person around 2–3 days per week.
- Participate in on-call coverage, including occasional nights and weekends.
- Work alongside internal incident responders, cross-functional IT and infrastructure teams, and analysts from the 24/7 MDR partner Rapid7.
- Tech stack and tools include Rapid7 InsightIDR, EDR/XDR platforms, Okta, Google Workspace, AWS/GCP, and custom Python/Bash automation scripts.
- Methodologies include framework-driven incident response aligned with MITRE ATT&CK, structured playbooks, and continuous threat-hunting cycles.
Read the full description and apply on the company’s own careers page.