Cyber Security Analyst
NewBe an early applicantPosition: Security Analyst
SOC Operations | 24x7 Shift | Noida / Bengaluru
About This Role
We are seeking a vigilant and technically proficient Security Analyst to join our Security Operations Center (SOC). This is a critical role responsible for 24x7 monitoring, detection, and response to security incidents. You will work with industry-leading security tools to identify threats, investigate security events, and provide actionable intelligence to protect our organizational assets.
Key Responsibilities
- Monitor and analyze security events and alerts from SIEM (IBM QRadar) in real-time
- Investigate suspected security incidents and create comprehensive incident reports
- Correlate and analyze logs from multiple security data sources and endpoints
- Respond to security alerts related to CrowdStrike Falcon endpoints and threat detection
- Manage and respond to Zscaler (ZIA/ZPA) security events and policy violations
- Review and analyze Data Loss Prevention (DLP) incidents and take appropriate action
- Monitor attack surface using specialized tools to identify external vulnerabilities
- Perform threat hunting and proactive threat identification
- Escalate critical incidents to senior analysts and management appropriately
- Maintain detailed documentation of all security events and investigations
- Collaborate with IT and business teams to remediate identified security issues
- Participate in security alerts, on-call support, and incident response drills
Required Qualifications
- 2+ years of experience in Security Operations Center (SOC) or cybersecurity role
- Proven hands-on experience with IBM QRadar SIEM platform
- Working knowledge of SIEM solutions and log management
- Hands-on experience with Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA)
- Strong experience with CrowdStrike Falcon platform and all its modules
- Experience with Data Loss Prevention (DLP) solutions and policies
- Familiarity with attack surface assessment and management tools
- Strong understanding of network fundamentals and protocols (TCP/IP, DNS, HTTP)
- Knowledge of common cyber threats, attack vectors, and attack methodologies
- Ability to work in a 24x7 shift rotation including night shifts and weekends
Required Technical Skills
- IBM QRadar SIEM: Correlation rules, event management, alert tuning, and custom searches
- CrowdStrike Falcon: Endpoint Detection and Response (EDR), behavioral analysis, threat hunting
- Zscaler Services: ZIA and ZPA configuration, security policy management, log analysis
- DLP Tools: Policy configuration, incident investigation, and false positive management
- Log Analysis: Interpreting security logs and events from diverse sources
- Network Protocol Analysis: Packet analysis (Wireshark), network traffic interpretation
- Endpoint Security: Antivirus, antimalware, host-based intrusion detection (HIDS)
- Attack Surface Visibility: External vulnerability scanning, asset discovery platforms
- Threat Intelligence: Utilizing threat feeds, IOCs, MITRE ATT&CK framework
- Windows & Linux Systems: Basic security concepts, process analysis, system hardening
- Incident Management: Ticketing systems (ServiceNow, Jira, Manage Engine), runbooks, escalation procedures
Preferred Qualifications & Skills
- Bachelor's degree in Computer Science, Information Security, or related field (or equivalent work experience)
- Experience with additional SIEM platforms (Splunk, ArcSight, SumoLogic)
- Knowledge of SOAR (Security Orchestration, Automation and Response) platforms
- Vulnerability assessment and management tools (Qualys, Tenable, Rapid7)
- Incident response frameworks (NIST Cybersecurity Framework, MITRE ATT&CK)
- Cloud security experience (AWS Security Hub, Azure Sentinel, GCP)
- Scripting knowledge (Python, PowerShell, Bash) for automation and analysis
- Security certifications: CompTIA Security+, CEH
- Experience with threat hunting and Advanced Persistent Threat (APT) analysis
- Malware analysis and reverse engineering basics
- Knowledge of proxy and firewall technologies
- Monitor and analyze security events and alerts from SIEM (IBM QRadar) in real-time
- Investigate suspected security incidents and create comprehensive incident reports
- Correlate and analyze logs from multiple security data sources and endpoints
- Respond to security alerts related to CrowdStrike Falcon endpoints and threat detection
- Manage and respond to Zscaler (ZIA/ZPA) security events and policy violations
- Review and analyze Data Loss Prevention (DLP) incidents and take appropriate action
- Monitor attack surface using specialized tools to identify external vulnerabilities
- Perform threat hunting and proactive threat identification
- Escalate critical incidents to senior analysts and management appropriately
- Maintain detailed documentation of all security events and investigations
- Collaborate with IT and business teams to remediate identified security issues
- Participate in security alerts, on-call support, and incident response drills
- 2+ years of experience in Security Operations Center (SOC) or cybersecurity role
- Proven hands-on experience with IBM QRadar SIEM platform
- Working knowledge of SIEM solutions and log management
- Hands-on experience with Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA)
- Strong experience with CrowdStrike Falcon platform and all its modules
- Experience with Data Loss Prevention (DLP) solutions and policies
- Familiarity with attack surface assessment and management tools
- Strong understanding of network fundamentals and protocols (TCP/IP, DNS, HTTP)
- Knowledge of common cyber threats, attack vectors, and attack methodologies
- Ability to work in a 24x7 shift rotation including night shifts and weekends