DIGITAL SECURITY - SOC Services
Summary
A SOC analyst monitors security events, investigates incidents, and hunts threats using Logpoint SIEM and related tools in a 24x7 Hyderabad office with rotational shifts.
Job Summary: Experience Profile (3 Years SOC Analyst)
✔ 3+ years in SOC Monitoring & Incident Handling
✔ Hands-on Logpoint (GuardSIX) SIEM operations
✔ Experience in alert triage and incident investigation
✔ Knowledge of EDR, Firewall, IDS/IPS, Email Security logs
✔ Familiarity with MITRE ATT&CK and Threat Hunting
✔ Working experience in a 24x7 SOC environment
Location: Hyderabad
Shift: 24x7 Rotational Shifts
Work Location: 5 days work from office(we can discuss about Night shifts)
Key Responsibilities
Security Monitoring & Incident Detection (Must have)
• Monitor security events and alerts generated from Logpoint SIEM (GuardSIX) and integrated security tools.
• Perform real-time analysis of security incidents and suspicious activities.
• Investigate alerts related to malware, phishing, ransomware, insider threats, privilege misuse, and unauthorized access.
• Validate and triage security alerts based on severity and business impact.
• Escalate incidents to L2 & L3 teams and stakeholders as per defined procedures.
Incident Response & Investigation (Must Have)
• Conduct incident investigations using SIEM queries and threat intelligence sources.
• Analyze logs from:
o Windows Servers & Workstations
o Linux Systems
o Active Directory
o Firewalls
o IDS/IPS
o Proxy and Web Gateways
o EDR/XDR Solutions
o Cloud Platforms (Azure, AWS, GCP)
• Perform root cause analysis and incident documentation.
• Support containment, eradication, and recovery activities.
Threat Hunting & Threat Intelligence (Must have)
• Execute proactive threat hunting activities using Logpoint searches.
• Leverage MITRE ATT&CK framework for threat mapping.
• Analyze Indicators of Compromise (IoCs).
• Correlate threat intelligence feeds with internal security events.
• Identify anomalous user and system behaviors.
Logpoint SIEM Administration & Use Case Monitoring (Good to have)
• Create, modify, and tune Logpoint correlation rules and use cases.
• Fine-tune alert thresholds to reduce false positives.
• Develop dashboards, reports, and custom searches.
• Monitor log collection health and data ingestion.
• Validate parser functionality and troubleshoot log collection issues.
• Perform use case validation and testing.
Required Technical Skills
SIEM
• Hands-on experience with:
o Logpoint SIEM (GuardSIX) – Mandatory
o Experience with Splunk/QRadar/Microsoft Sentinel (Preferred)
Security Technologies
• Firewalls (Palo Alto, Fortinet, Check Point, Cisco)
• IDS/IPS (Snort, Suricata, Trend Micro)
• EDR/XDR (Microsoft Defender, CrowdStrike, SentinelOne)
• Email Security Solutions
• Web Proxy Solutions
• Vulnerability Management Tools
Operating Systems
• Windows Administration
• Linux Administration
Networking
• TCP/IP
• DNS
• DHCP
• VPN
• HTTP/HTTPS
• SMTP
• Network Security Concepts
Required Knowledge
• Cyber Kill Chain
• MITRE ATT&CK Framework
• Security Incident Response Lifecycle
• Threat Intelligence Concepts
• Malware Analysis Fundamentals
• Security Monitoring Best Practices
• SOC Processes and Procedures
• Event Correlation Techniques
Qualifications
• Bachelor's Degree in Computer Science, Information Security, IT, or related field.
• 3+ years of experience in SOC operations.
• Experience working in 24x7 rotational shifts.
• Strong analytical and troubleshooting skills.
• Excellent verbal and written communication skills.
Preferred Certifications
• CompTIA Security+
• CEH (Certified Ethical Hacker)
• SC-200 (Microsoft Security Operations Analyst)
• Logpoint Certified Analyst (Preferred)
Key Performance Indicators (KPIs)
• Incident Response SLA Compliance
• Mean Time to Detect (MTTD)
• Mean Time to Respond (MTTR)
• Alert Triage Accuracy
• Use Case Effectiveness
• Threat Hunt Outcomes
• Reduction in False Positive Alerts
Job Summary: Experience Profile (3 Years SOC Analyst)
✔ 3+ years in SOC Monitoring & Incident Handling
✔ Hands-on Logpoint (GuardSIX) SIEM operations
✔ Experience in alert triage and incident investigation
✔ Knowledge of EDR, Firewall, IDS/IPS, Email Security logs
✔ Familiarity with MITRE ATT&CK and Threat Hunting
✔ Working experience in a 24x7 SOC environment
Location: Hyderabad
Shift: 24x7 Rotational Shifts
Work Location: 5 days work from office(we can discuss about Night shifts)
Key Responsibilities
Security Monitoring & Incident Detection (Must have)
• Monitor security events and alerts generated from Logpoint SIEM (GuardSIX) and integrated security tools.
• Perform real-time analysis of security incidents and suspicious activities.
• Investigate alerts related to malware, phishing, ransomware, insider threats, privilege misuse, and unauthorized access.
• Validate and triage security alerts based on severity and business impact.
• Escalate incidents to L2 & L3 teams and stakeholders as per defined procedures.
Incident Response & Investigation (Must Have)
• Conduct incident investigations using SIEM queries and threat intelligence sources.
• Analyze logs from:
o Windows Servers & Workstations
o Linux Systems
o Active Directory
o Firewalls
o IDS/IPS
o Proxy and Web Gateways
o EDR/XDR Solutions
o Cloud Platforms (Azure, AWS, GCP)
• Perform root cause analysis and incident documentation.
• Support containment, eradication, and recovery activities.
Threat Hunting & Threat Intelligence (Must have)
• Execute proactive threat hunting activities using Logpoint searches.
• Leverage MITRE ATT&CK framework for threat mapping.
• Analyze Indicators of Compromise (IoCs).
• Correlate threat intelligence feeds with internal security events.
• Identify anomalous user and system behaviors.
Logpoint SIEM Administration & Use Case Monitoring (Good to have)
• Create, modify, and tune Logpoint correlation rules and use cases.
• Fine-tune alert thresholds to reduce false positives.
• Develop dashboards, reports, and custom searches.
• Monitor log collection health and data ingestion.
• Validate parser functionality and troubleshoot log collection issues.
• Perform use case validation and testing.
Required Technical Skills
SIEM
• Hands-on experience with:
o Logpoint SIEM (GuardSIX) – Mandatory
o Experience with Splunk/QRadar/Microsoft Sentinel (Preferred)
Security Technologies
• Firewalls (Palo Alto, Fortinet, Check Point, Cisco)
• IDS/IPS (Snort, Suricata, Trend Micro)
• EDR/XDR (Microsoft Defender, CrowdStrike, SentinelOne)
• Email Security Solutions
• Web Proxy Solutions
• Vulnerability Management Tools
Operating Systems
• Windows Administration
• Linux Administration
Networking
• TCP/IP
• DNS
• DHCP
• VPN
• HTTP/HTTPS
• SMTP
• Network Security Concepts
Required Knowledge
• Cyber Kill Chain
• MITRE ATT&CK Framework
• Security Incident Response Lifecycle
• Threat Intelligence Concepts
• Malware Analysis Fundamentals
• Security Monitoring Best Practices
• SOC Processes and Procedures
• Event Correlation Techniques
Qualifications
• Bachelor's Degree in Computer Science, Information Security, IT, or related field.
• 3+ years of experience in SOC operations.
• Experience working in 24x7 rotational shifts.
• Strong analytical and troubleshooting skills.
• Excellent verbal and written communication skills.
Preferred Certifications
• CompTIA Security+
• CEH (Certified Ethical Hacker)
• SC-200 (Microsoft Security Operations Analyst)
• Logpoint Certified Analyst (Preferred)
Key Performance Indicators (KPIs)
• Incident Response SLA Compliance
• Mean Time to Detect (MTTD)
• Mean Time to Respond (MTTR)
• Alert Triage Accuracy
• Use Case Effectiveness
• Threat Hunt Outcomes
• Reduction in False Positive Alerts
Job Summary: Experience Profile (3 Years SOC Analyst)
✔ 3+ years in SOC Monitoring & Incident Handling
✔ Hands-on Logpoint (GuardSIX) SIEM operations
✔ Experience in alert triage and incident investigation
✔ Knowledge of EDR, Firewall, IDS/IPS, Email Security logs
✔ Familiarity with MITRE ATT&CK and Threat Hunting
✔ Working experience in a 24x7 SOC environment
Location: Hyderabad
Shift: 24x7 Rotational Shifts
Work Location: 5 days work from office(we can discuss about Night shifts)
Key Responsibilities
Security Monitoring & Incident Detection (Must have)
• Monitor security events and alerts generated from Logpoint SIEM (GuardSIX) and integrated security tools.
• Perform real-time analysis of security incidents and suspicious activities.
• Investigate alerts related to malware, phishing, ransomware, insider threats, privilege misuse, and unauthorized access.
• Validate and triage security alerts based on severity and business impact.
• Escalate incidents to L2 & L3 teams and stakeholders as per defined procedures.
Incident Response & Investigation (Must Have)
• Conduct incident investigations using SIEM queries and threat intelligence sources.
• Analyze logs from:
o Windows Servers & Workstations
o Linux Systems
o Active Directory
o Firewalls
o IDS/IPS
o Proxy and Web Gateways
o EDR/XDR Solutions
o Cloud Platforms (Azure, AWS, GCP)
• Perform root cause analysis and incident documentation.
• Support containment, eradication, and recovery activities.
Threat Hunting & Threat Intelligence (Must have)
• Execute proactive threat hunting activities using Logpoint searches.
• Leverage MITRE ATT&CK framework for threat mapping.
• Analyze Indicators of Compromise (IoCs).
• Correlate threat intelligence feeds with internal security events.
• Identify anomalous user and system behaviors.
Logpoint SIEM Administration & Use Case Monitoring (Good to have)
• Create, modify, and tune Logpoint correlation rules and use cases.
• Fine-tune alert thresholds to reduce false positives.
• Develop dashboards, reports, and custom searches.
• Monitor log collection health and data ingestion.
• Validate parser functionality and troubleshoot log collection issues.
• Perform use case validation and testing.
Required Technical Skills
SIEM
• Hands-on experience with:
o Logpoint SIEM (GuardSIX) – Mandatory
o Experience with Splunk/QRadar/Microsoft Sentinel (Preferred)
Security Technologies
• Firewalls (Palo Alto, Fortinet, Check Point, Cisco)
• IDS/IPS (Snort, Suricata, Trend Micro)
• EDR/XDR (Microsoft Defender, CrowdStrike, SentinelOne)
• Email Security Solutions
• Web Proxy Solutions
• Vulnerability Management Tools
Operating Systems
• Windows Administration
• Linux Administration
Networking
• TCP/IP
• DNS
• DHCP
• VPN
• HTTP/HTTPS
• SMTP
• Network Security Concepts
Required Knowledge
• Cyber Kill Chain
• MITRE ATT&CK Framework
• Security Incident Response Lifecycle
• Threat Intelligence Concepts
• Malware Analysis Fundamentals
• Security Monitoring Best Practices
• SOC Processes and Procedures
• Event Correlation Techniques
Qualifications
• Bachelor's Degree in Computer Science, Information Security, IT, or related field.
• 3+ years of experience in SOC operations.
• Experience working in 24x7 rotational shifts.
• Strong analytical and troubleshooting skills.
• Excellent verbal and written communication skills.
Preferred Certifications
• CompTIA Security+
• CEH (Certified Ethical Hacker)
• SC-200 (Microsoft Security Operations Analyst)
• Logpoint Certified Analyst (Preferred)
Key Performance Indicators (KPIs)
• Incident Response SLA Compliance
• Mean Time to Detect (MTTD)
• Mean Time to Respond (MTTR)
• Alert Triage Accuracy
• Use Case Effectiveness
• Threat Hunt Outcomes
• Reduction in False Positive Alerts