NOC + SOC Analyst (L1)
Summary
An L1 NOC + SOC analyst in Chennai monitoring network, cloud, server, and security environments on 24x7 rotational shifts. Day to day: triaging and troubleshooting alerts from SIEM, EDR/XDR, firewalls and cloud platforms, managing incidents in ITSM tools, and escalating critical events to L2.
NOC + SOC Analyst (L1)
Experience: 2-4 Years
Location: Chennai
Shift: 24x7 Rotational Shifts
Role Summary
We are seeking a proactive NOC + SOC
Analyst (L1) to provide first-level monitoring, alert triage, incident
management, and operational support across network, cloud, infrastructure, and
security environments. The role will be responsible for continuous monitoring
of operational and security queues, performing initial investigations,
executing runbooks, and ensuring timely escalation of incidents to L2 teams
while maintaining SLA adherence. The ideal candidate should possess hands-on
experience with monitoring platforms, endpoint security tools, security alert
analysis, and data-driven troubleshooting.
Key Responsibilities
Infrastructure & Network Operations
- Monitor infrastructure, cloud, application, and network health
using Datadog and other monitoring platforms.
- Perform initial troubleshooting of server, network, cloud, and
application alerts.
- Identify service degradation, outages, and performance
anomalies.
- Create, update, and manage incidents through ITSM platforms.
- Escalate unresolved issues to appropriate technical teams
following established procedures.
Security Operations
- Monitor and triage security alerts generated by CrowdStrike,
cloud platforms, identity services, and security monitoring tools.
- Analyze endpoint, identity, cloud, and authentication-related
events.
- Perform first-level investigation and validation of security
incidents.
- Execute documented runbooks and escalation procedures for
security events.
- Ensure rapid escalation of high-priority and suspicious
activities to SOC L2 teams.
Incident & Queue Management
- Maintain operational and security queue coverage during
assigned shifts.
- Perform evidence-based alert disposition and documentation.
- Ensure incidents are categorized, prioritized, and updated
accurately.
- Support incident response activities and service restoration
efforts.
- Provide comprehensive shift handovers with clear status updates
and pending actions.
Data Analysis & Reporting
- Perform basic log analysis using Databricks and SQL queries.
- Investigate operational and security events using data from
multiple sources.
- Assist in trend analysis, recurring issue identification, and
reporting activities.
- Support operational dashboards and monitoring reviews.
Technical Skills
Monitoring & Operations
- Datadog (Preferred)
- ServiceNow or Jira or equivalent ITSM platforms
- Infrastructure and application monitoring concepts
Security Operations
- CrowdStrike Falcon
- Microsoft Defender / EDR-XDR concepts
- SIEM fundamentals (Sentinel, Splunk, QRadar, or similar)
- Security alert triage and incident management
Cloud & Infrastructure
- Windows Server and Linux administration fundamentals
- Active Directory / Entra ID
- Microsoft Azure and AWS fundamentals
- TCP/IP, DNS, DHCP, VPN, Routing & Switching
Data Analysis
- Basic Databricks knowledge
- SQL query execution and analysis
- Log analysis and event correlation
Preferred Certifications
- ITIL 4 Foundation
- Microsoft SC-900
- CompTIA Security+
- AZ-900 or AWS Cloud Practitioner
- CrowdStrike Falcon Fundamentals (Preferred)
- Datadog Fundamentals Certification (Preferred)
- CCNA (Added Advantage)
Required Competencies
- Strong troubleshooting and analytical skills
- Ability to investigate alerts across network, endpoint, cloud,
and identity environments
- Good documentation and communication skills
- Ability to follow runbooks and operational procedures
- Experience working in a 24x7 support environment
- Customer-focused mindset with strong collaboration skills
- Ability to provide structured and high-quality shift handovers