DIGITAL SECURITY - SOC Services

Summary

Monitor and respond to security incidents 24/7 using Logpoint SIEM, investigating threats like malware and phishing while handling alerts from firewalls, EDR, and cloud platforms in a Hyderabad-based SOC.

Job Summary: Experience Profile (3 Years SOC Analyst)

3+ years in SOC Monitoring & Incident Handling

Hands-on Logpoint (GuardSIX) SIEM operations

Experience in alert triage and incident investigation

Knowledge of EDR, Firewall, IDS/IPS, Email Security logs

Familiarity with MITRE ATT&CK and Threat Hunting

Working experience in a 24x7 SOC environment

Location: Hyderabad

Shift: 24x7 Rotational Shifts

Work Location: 5 days work from office(we can discuss about Night shifts)

Key Responsibilities

Security Monitoring & Incident Detection (Must have)

•     Monitor security events and alerts generated from Logpoint SIEM (GuardSIX) and integrated security tools.

•     Perform real-time analysis of security incidents and suspicious activities.

•     Investigate alerts related to malware, phishing, ransomware, insider threats, privilege misuse, and unauthorized access.

•     Validate and triage security alerts based on severity and business impact.

•     Escalate incidents to L2 & L3 teams and stakeholders as per defined procedures.

Incident Response & Investigation (Must Have)

•     Conduct incident investigations using SIEM queries and threat intelligence sources.

•     Analyze logs from:

o     Windows Servers & Workstations

o     Linux Systems

o     Active Directory

o     Firewalls

o     IDS/IPS

o     Proxy and Web Gateways

o     EDR/XDR Solutions

o     Cloud Platforms (Azure, AWS, GCP)

•     Perform root cause analysis and incident documentation.

•     Support containment, eradication, and recovery activities.

Threat Hunting & Threat Intelligence (Must have)

•     Execute proactive threat hunting activities using Logpoint searches.

•     Leverage MITRE ATT&CK framework for threat mapping.

•     Analyze Indicators of Compromise (IoCs).

•     Correlate threat intelligence feeds with internal security events.

•     Identify anomalous user and system behaviors.

Logpoint SIEM Administration & Use Case Monitoring (Good to have)

•     Create, modify, and tune Logpoint correlation rules and use cases.

•     Fine-tune alert thresholds to reduce false positives.

•     Develop dashboards, reports, and custom searches.

•     Monitor log collection health and data ingestion.

•     Validate parser functionality and troubleshoot log collection issues.

•     Perform use case validation and testing.

Required Technical Skills

SIEM

•     Hands-on experience with:

o     Logpoint SIEM (GuardSIX) – Mandatory

o     Experience with Splunk/QRadar/Microsoft Sentinel (Preferred)

Security Technologies

•     Firewalls (Palo Alto, Fortinet, Check Point, Cisco)

•     IDS/IPS (Snort, Suricata, Trend Micro)

•     EDR/XDR (Microsoft Defender, CrowdStrike, SentinelOne)

•     Email Security Solutions

•     Web Proxy Solutions

•     Vulnerability Management Tools

Operating Systems

•     Windows Administration

•     Linux Administration

Networking

•     TCP/IP

•     DNS

•     DHCP

•     VPN

•     HTTP/HTTPS

•     SMTP

•     Network Security Concepts

Required Knowledge

•     Cyber Kill Chain

•     MITRE ATT&CK Framework

•     Security Incident Response Lifecycle

•     Threat Intelligence Concepts

•     Malware Analysis Fundamentals

•     Security Monitoring Best Practices

•     SOC Processes and Procedures

•     Event Correlation Techniques

Qualifications

•     Bachelor's Degree in Computer Science, Information Security, IT, or related field.

•     3+ years of experience in SOC operations.

•     Experience working in 24x7 rotational shifts.

•     Strong analytical and troubleshooting skills.

•     Excellent verbal and written communication skills.

Preferred Certifications

•     CompTIA Security+

•     CEH (Certified Ethical Hacker)

•     SC-200 (Microsoft Security Operations Analyst)

•     Logpoint Certified Analyst (Preferred)

Key Performance Indicators (KPIs)

•     Incident Response SLA Compliance

•     Mean Time to Detect (MTTD)

•     Mean Time to Respond (MTTR)

•     Alert Triage Accuracy

•     Use Case Effectiveness

•     Threat Hunt Outcomes

•     Reduction in False Positive Alerts

Job Summary: Experience Profile (3 Years SOC Analyst)

3+ years in SOC Monitoring & Incident Handling

Hands-on Logpoint (GuardSIX) SIEM operations

Experience in alert triage and incident investigation

Knowledge of EDR, Firewall, IDS/IPS, Email Security logs

Familiarity with MITRE ATT&CK and Threat Hunting

Working experience in a 24x7 SOC environment

Location: Hyderabad

Shift: 24x7 Rotational Shifts

Work Location: 5 days work from office(we can discuss about Night shifts)

Key Responsibilities

Security Monitoring & Incident Detection (Must have)

•     Monitor security events and alerts generated from Logpoint SIEM (GuardSIX) and integrated security tools.

•     Perform real-time analysis of security incidents and suspicious activities.

•     Investigate alerts related to malware, phishing, ransomware, insider threats, privilege misuse, and unauthorized access.

•     Validate and triage security alerts based on severity and business impact.

•     Escalate incidents to L2 & L3 teams and stakeholders as per defined procedures.

Incident Response & Investigation (Must Have)

•     Conduct incident investigations using SIEM queries and threat intelligence sources.

•     Analyze logs from:

o     Windows Servers & Workstations

o     Linux Systems

o     Active Directory

o     Firewalls

o     IDS/IPS

o     Proxy and Web Gateways

o     EDR/XDR Solutions

o     Cloud Platforms (Azure, AWS, GCP)

•     Perform root cause analysis and incident documentation.

•     Support containment, eradication, and recovery activities.

Threat Hunting & Threat Intelligence (Must have)

•     Execute proactive threat hunting activities using Logpoint searches.

•     Leverage MITRE ATT&CK framework for threat mapping.

•     Analyze Indicators of Compromise (IoCs).

•     Correlate threat intelligence feeds with internal security events.

•     Identify anomalous user and system behaviors.

Logpoint SIEM Administration & Use Case Monitoring (Good to have)

•     Create, modify, and tune Logpoint correlation rules and use cases.

•     Fine-tune alert thresholds to reduce false positives.

•     Develop dashboards, reports, and custom searches.

•     Monitor log collection health and data ingestion.

•     Validate parser functionality and troubleshoot log collection issues.

•     Perform use case validation and testing.

Required Technical Skills

SIEM

•     Hands-on experience with:

o     Logpoint SIEM (GuardSIX) – Mandatory

o     Experience with Splunk/QRadar/Microsoft Sentinel (Preferred)

Security Technologies

•     Firewalls (Palo Alto, Fortinet, Check Point, Cisco)

•     IDS/IPS (Snort, Suricata, Trend Micro)

•     EDR/XDR (Microsoft Defender, CrowdStrike, SentinelOne)

•     Email Security Solutions

•     Web Proxy Solutions

•     Vulnerability Management Tools

Operating Systems

•     Windows Administration

•     Linux Administration

Networking

•     TCP/IP

•     DNS

•     DHCP

•     VPN

•     HTTP/HTTPS

•     SMTP

•     Network Security Concepts

Required Knowledge

•     Cyber Kill Chain

•     MITRE ATT&CK Framework

•     Security Incident Response Lifecycle

•     Threat Intelligence Concepts

•     Malware Analysis Fundamentals

•     Security Monitoring Best Practices

•     SOC Processes and Procedures

•     Event Correlation Techniques

Qualifications

•     Bachelor's Degree in Computer Science, Information Security, IT, or related field.

•     3+ years of experience in SOC operations.

•     Experience working in 24x7 rotational shifts.

•     Strong analytical and troubleshooting skills.

•     Excellent verbal and written communication skills.

Preferred Certifications

•     CompTIA Security+

•     CEH (Certified Ethical Hacker)

•     SC-200 (Microsoft Security Operations Analyst)

•     Logpoint Certified Analyst (Preferred)

Key Performance Indicators (KPIs)

•     Incident Response SLA Compliance

•     Mean Time to Detect (MTTD)

•     Mean Time to Respond (MTTR)

•     Alert Triage Accuracy

•     Use Case Effectiveness

•     Threat Hunt Outcomes

•     Reduction in False Positive Alerts

Job Summary: Experience Profile (3 Years SOC Analyst)

3+ years in SOC Monitoring & Incident Handling

Hands-on Logpoint (GuardSIX) SIEM operations

Experience in alert triage and incident investigation

Knowledge of EDR, Firewall, IDS/IPS, Email Security logs

Familiarity with MITRE ATT&CK and Threat Hunting

Working experience in a 24x7 SOC environment

Location: Hyderabad

Shift: 24x7 Rotational Shifts

Work Location: 5 days work from office(we can discuss about Night shifts)

Key Responsibilities

Security Monitoring & Incident Detection (Must have)

•     Monitor security events and alerts generated from Logpoint SIEM (GuardSIX) and integrated security tools.

•     Perform real-time analysis of security incidents and suspicious activities.

•     Investigate alerts related to malware, phishing, ransomware, insider threats, privilege misuse, and unauthorized access.

•     Validate and triage security alerts based on severity and business impact.

•     Escalate incidents to L2 & L3 teams and stakeholders as per defined procedures.

Incident Response & Investigation (Must Have)

•     Conduct incident investigations using SIEM queries and threat intelligence sources.

•     Analyze logs from:

o     Windows Servers & Workstations

o     Linux Systems

o     Active Directory

o     Firewalls

o     IDS/IPS

o     Proxy and Web Gateways

o     EDR/XDR Solutions

o     Cloud Platforms (Azure, AWS, GCP)

•     Perform root cause analysis and incident documentation.

•     Support containment, eradication, and recovery activities.

Threat Hunting & Threat Intelligence (Must have)

•     Execute proactive threat hunting activities using Logpoint searches.

•     Leverage MITRE ATT&CK framework for threat mapping.

•     Analyze Indicators of Compromise (IoCs).

•     Correlate threat intelligence feeds with internal security events.

•     Identify anomalous user and system behaviors.

Logpoint SIEM Administration & Use Case Monitoring (Good to have)

•     Create, modify, and tune Logpoint correlation rules and use cases.

•     Fine-tune alert thresholds to reduce false positives.

•     Develop dashboards, reports, and custom searches.

•     Monitor log collection health and data ingestion.

•     Validate parser functionality and troubleshoot log collection issues.

•     Perform use case validation and testing.

Required Technical Skills

SIEM

•     Hands-on experience with:

o     Logpoint SIEM (GuardSIX) – Mandatory

o     Experience with Splunk/QRadar/Microsoft Sentinel (Preferred)

Security Technologies

•     Firewalls (Palo Alto, Fortinet, Check Point, Cisco)

•     IDS/IPS (Snort, Suricata, Trend Micro)

•     EDR/XDR (Microsoft Defender, CrowdStrike, SentinelOne)

•     Email Security Solutions

•     Web Proxy Solutions

•     Vulnerability Management Tools

Operating Systems

•     Windows Administration

•     Linux Administration

Networking

•     TCP/IP

•     DNS

•     DHCP

•     VPN

•     HTTP/HTTPS

•     SMTP

•     Network Security Concepts

Required Knowledge

•     Cyber Kill Chain

•     MITRE ATT&CK Framework

•     Security Incident Response Lifecycle

•     Threat Intelligence Concepts

•     Malware Analysis Fundamentals

•     Security Monitoring Best Practices

•     SOC Processes and Procedures

•     Event Correlation Techniques

Qualifications

•     Bachelor's Degree in Computer Science, Information Security, IT, or related field.

•     3+ years of experience in SOC operations.

•     Experience working in 24x7 rotational shifts.

•     Strong analytical and troubleshooting skills.

•     Excellent verbal and written communication skills.

Preferred Certifications

•     CompTIA Security+

•     CEH (Certified Ethical Hacker)

•     SC-200 (Microsoft Security Operations Analyst)

•     Logpoint Certified Analyst (Preferred)

Key Performance Indicators (KPIs)

•     Incident Response SLA Compliance

•     Mean Time to Detect (MTTD)

•     Mean Time to Respond (MTTR)

•     Alert Triage Accuracy

•     Use Case Effectiveness

•     Threat Hunt Outcomes

•     Reduction in False Positive Alerts