Overview
Security Analyst (SOC Analyst) responsible for owning alert triage, incident investigation, and response during non-US business hours.
What you'll do
- Own the incident lifecycle during non-US hours from triage through containment, remediation, and documentation.
- Investigate security events across SIEM, EDR, email security, network, identity, and cloud platforms.
- Perform root cause analysis and produce actionable incident reports.
- Escalate incidents to the Director of Security Operations with situation summaries and recommended actions.
- Develop and maintain incident response playbooks and SOC runbooks.
- Provide detailed shift handoff notes to the US-based security analyst to ensure continuity.
What you'll need
- Bachelor’s degree in Computer Science/IT/Electronics or related field (B.E./B.Tech/BCA/B.Sc. IT preferred).
- 4–6 years of experience in SOC or cybersecurity operations, performing both L2 investigation and L3 response duties.
- Hands-on experience with SIEM platforms (Splunk, Microsoft Sentinel, IBM QRadar, or similar).
- Strong experience with EDR tools (CrowdStrike Falcon, Microsoft Defender, SentinelOne, or similar).
- Advanced log analysis skills across Windows, Linux, cloud (AWS, Azure, GCP), and identity platforms (Active Directory, Azure AD).
- Strong working knowledge of the MITRE ATT&CK framework.
- Comfortable working non-US business hours.
Details
Read the full description and apply on the company’s own careers page.