Locations Supported
India - Bengaluru
Relocation available: No
Work pattern:
This role will be on-site
Rotational Shifts
24x7 follow-the-sun model
About the Opportunity
Join the Security Operations Center as a SOC Analyst, a critical frontline role responsible for protecting the organization against security threats and operational disruptions across 24×7 rotation. You'll be at the intersection of security and operations, monitoring real-time alerts, investigating suspicious activity, responding to incidents, and supporting infrastructure operations. This role is perfect for someone who thrives in a fast-paced environment where multiple security and IT issues can converge at once, and who wants to build deep expertise across both security-focused and operational-support workflows.
What You Will Do
Monitor real-time security alerts and investigate suspicious network, endpoint, and cloud activity through SIEM queries and threat-analysis tools to detect emerging threats.
Identify, declare, document, and escalate security incidents in line with established incident-response (IR) playbooks, ensuring rapid containment and remediation.
Analyze and remediate email-based threats including phishing, malware, spoofing attempts, and manage endpoint device security through EDR workflows and MDM policies.
Act as the first-line point of contact for IT requests including password resets, account unlocks, hardware provisioning, email/collaboration-platform issues, and application access problems
Maintain accurate and timely ticket documentation, case notes, and incident summaries, contribute to runbook improvements, process documentation, and knowledge base articles to support team efficiency.
Monitor external attack surface including brand-impersonation activity, fraudulent domain registrations, social-engineering threats, and validate honeytoken decoys to detect unauthorized lateral-movement attempts.
About You
Must-have experience and skills
2+ years of hands-on experience in a Security Operations Center, security monitoring, or incident-response role, demonstrated ability to triage alerts, investigate incidents, and execute incident-response procedures.
Experience investigating data-exfiltration indicators including unusual file transfers, large data-volume anomalies, credential harvesting attempts, and unauthorized cloud-service access
Solid understanding of IT infrastructure concepts including networks (IP, DNS, ports, protocols), endpoints (macOS), and identity systems (IAM, SSO, MFA).
Experience with incident-response frameworks (MITRE ATT&CK), incident-command models and familiarity with ticketing systems (Jira, Linear or similar).
Detail-oriented with strong documentation discipline. Able to write clear, concise incident summaries and shift notes, reliable follow-through on tasks and comfortable asking clarifying questions rather than making assumptions.
Proactive problem-solver and analytical-thinker with sound judgment about when to escalate vs. when to investigate further.
Nice-to-have experience
Bachelor's degree in Cybersecurity, Computer Science or Information Technology.
Proficiency with Okta for SSO/authentication workflows, admin console operations, and user access management is highly preferred.
Experience with Jamf for Apple/macOS device management
Exposure to Google SecOps, DoControl, Code42 and Cloudflare email security.

