Overview
SOC Analyst role in Bengaluru, focused on protecting the organization by monitoring alerts, investigating suspicious activity, responding to incidents, and supporting security and operational workflows through a 24x7 rotational model.
What you'll do
- Monitor real-time security alerts and investigate suspicious network, endpoint, and cloud activity using SIEM queries and threat-analysis tools.
- Identify, document, and escalate security incidents using established incident-response playbooks for containment and remediation.
- Analyze and remediate email-based threats (phishing, malware, spoofing) and manage endpoint security via EDR workflows and MDM policies.
- Handle first-line IT requests including password resets, account unlocks, hardware provisioning, email/collaboration issues, and application access problems.
- Maintain accurate ticket documentation and incident summaries, and contribute to runbook/process and knowledge base updates.
- Monitor external attack surface activity (brand impersonation, fraudulent domains, social-engineering threats) and validate honeytoken decoys for lateral-movement attempts.
What you'll need
- 2+ years of hands-on experience in a Security Operations Center, security monitoring, or incident-response role.
- Ability to triage alerts, investigate incidents, and execute incident-response procedures.
- Experience investigating data-exfiltration indicators (unusual file transfers, large data-volume anomalies, credential harvesting, and unauthorized cloud-service access).
- Solid understanding of IT infrastructure concepts including networks (IP, DNS, ports, protocols), endpoints (macOS), and identity systems (IAM, SSO, MFA).
- Experience with incident-response frameworks (MITRE ATT&CK) and familiarity with ticketing systems (Jira, Linear or similar).
- Strong documentation discipline and ability to write clear incident summaries and shift notes.
Nice to have
- Bachelor's degree in Cybersecurity, Computer Science, or Information Technology.
- Proficiency with Okta (SSO/authentication workflows, admin console, user access management).
- Experience with Jamf for Apple/macOS device management.
- Exposure to Google SecOps, DoControl, Code42, and Cloudflare email security.
Details
- Location: Bengaluru, Karnataka.
- Work pattern: on-site with rotational shifts under a 24x7 follow-the-sun model.
- Relocation available: No.